This policy applies to every repository under
mukoko-dev, the Mukoko super app and
its mini-apps, unless that repository ships its own SECURITY.md with
different terms. It mirrors the canonical Nyuchi Africa security policy
at
nyuchi/.github → SECURITY.md.
Do not open a public issue, pull request, or discussion for a suspected vulnerability. Public disclosure before a fix is available puts users at risk.
You have two private channels. Use whichever you prefer.
On the affected repository: Security tab → Report a vulnerability. Only that repository's maintainers see the report. This is available on the public repositories in this organisation.
Send a report to security@nyuchi.com, the address the Mukoko repositories already publish. Use email for a private repository, or when you are not sure which repository is affected.
A good report lets us reproduce and assess quickly:
- A descriptive title.
- Repository, package, version, and commit SHA affected.
- The affected Mukoko app and URL, if it is a live deployment.
- A clear description of the vulnerability and its impact.
- Steps to reproduce, ideally with a minimal proof of concept.
- Logs, screenshots, or traffic captures that help.
- Your suggested remediation, if you have one.
- Whether you would like to be credited in the advisory.
When you report a vulnerability in good faith, we commit to:
- Acknowledging receipt within 3 business days.
- Initial assessment within 10 business days.
- Keeping you informed about remediation progress.
- Coordinating disclosure timing with you and crediting you in the published advisory unless you ask us not to.
In scope:
- Every repository under
mukoko-dev. - Production deployments of those repositories under
mukoko.com(for exampleaccounts.mukoko.com,events.mukoko.com,weather.mukoko.com,kweli.mukoko.com).
Out of scope (report to the relevant organisation):
- Repositories under
nyuchi, including Mukoko News and the Nyuchi API — seenyuchi/.github → SECURITY.md. - The Mzizi design system in
mzizi-devand the Bundu Foundation's repositories inbundu-labs— use the Security tab on the affected repository there. - Third-party services we integrate with — please report directly.
Some repositories add stricter terms (response SLAs, additional scope, specific environment notes). The repo-level file always wins for that repo — but it cannot relax the terms here.