OpenGov Africa handles sensitive data, including information relating to public officials, government expenditure, and civic activity. We take the security of our platform, repositories, and contributors’ data seriously.
If you discover a security vulnerability in any OpenGov Africa repository, service, or dataset, please report it privately rather than opening a public issue.
- Email: security@opengovafrica.org
- Alternative contact: citizens@opengovafrica.org (mark subject line “SECURITY”)
- Response time: We aim to acknowledge reports within 5 business days and provide an initial assessment within 14 days.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue.
- Any relevant logs, screenshots, or proof-of-concept code.
- Your contact information, if you wish to be credited or updated on resolution.
This policy covers:
- OpenGov Africa’s public GitHub repositories and associated infrastructure.
- Data pipelines and tools used to collect, verify, and publish civic data.
- Any web or application interfaces maintained by OpenGov Africa.
This policy does not cover third-party services we link to but do not operate.
We ask security researchers to:
- Give us reasonable time to investigate and remediate an issue before public disclosure.
- Avoid accessing, modifying, or deleting data beyond what is necessary to demonstrate a vulnerability.
- Avoid actions that could degrade service availability for other users, including denial-of-service testing.
We will not pursue legal action against researchers who act in good faith and comply with this policy.
Because some datasets reference civil society activity and individuals, a security failure could carry safety consequences for real people, not only data-integrity consequences. Reports involving potential exposure of personal data, including participant information related to civic action datasets, should be flagged as high priority in the report subject line.
OpenGov Africa is a rolling, community-maintained project. Security fixes are applied to the main branch of affected repositories; there are no separate long-term-support branches at this time.
With the reporter’s consent, we will credit valid reports in release notes or a security acknowledgments page.