Security Policy & Vulnerability Disclosure
Yene Restaurant takes the security of our platform and our customers' data seriously. This page describes how to responsibly report security vulnerabilities and what to expect from us in return.
repuxt@gmail.com
Within 48 hours
Within 90 days
If you believe you have discovered a security vulnerability in Yene Restaurant — the customer ordering platform, staff dashboard, or any supporting infrastructure hosted under *.yenerestaurant.com — please report it to us immediately.
Email a detailed report to repuxt@gmail.com. Include a clear description of the issue, the affected endpoint or component, step-by-step reproduction instructions, and the potential impact. If possible, attach proof-of-concept artifacts (HTTP traces, screenshots, payloads) with any credentials redacted.
Please do not file public GitHub issues, social-media posts, or customer-support tickets for security reports — those channels are not monitored for security disclosures and may expose the issue before we can remediate it.
We commit to acknowledging receipt of every credible security report within 48 hours of submission. The acknowledgement will be sent from repuxt@gmail.com and will include a tracking reference for follow-up.
Our engineering team will validate the report, assign a severity rating (Critical / High / Medium / Low based on CVSS v3.1), and provide an initial remediation plan within 7 business days for Critical and High issues and 14 business days for Medium and Low issues.
A fix or mitigation will be shipped to production within 90 days of the initial report. If a longer window is required (for example, due to coordinated disclosure with an upstream vendor), we will notify the reporter and agree on a revised timeline.
In scope: the production deployment at https://yenerestaurant.com and all subdomains, the customer-facing QR menu flow, the staff and owner dashboard, the public REST and Server-Sent-Events APIs under /api/, the payment integration surfaces (StarPay callbacks and verification endpoints), and the file-upload pipeline.
Out of scope: third-party services we do not operate (e.g. StarPay, OTP/SMS providers, CDN nodes), issues requiring physical access to user devices, denial-of-service attacks that can only be demonstrated by volumetric flooding, and self-XSS or social-engineering attacks that require the victim to attack themselves.
Vulnerabilities in out-of-scope systems should be reported directly to the relevant vendor per their own disclosure policy.
We support coordinated disclosure and will not pursue legal action against reporters who act in good faith, respect the rules below, and avoid harming Yene Restaurant users, staff, or business operations.
Test only accounts and data you own or have explicit permission to access. Do not access, modify, exfiltrate, or destroy data belonging to other restaurants, customers, or staff. Do not degrade service availability for other tenants.
Once a vulnerability is reported, do not publicly disclose it until we have shipped a fix or until 90 days have elapsed since the report, whichever comes first. We will credit reporters by name (or anonymously on request) in our release notes when the fix is published.
We are grateful to the security research community. Researchers who report a previously-unknown, in-scope, validated vulnerability will be acknowledged in our quarterly security advisories and may be eligible for a thank-you reward at our discretion.
We will not reward reports for out-of-scope issues, reports that do not include reproduction steps, or duplicates of already-known issues. The decision on eligibility is at Yene Restaurant's discretion and is final.
This policy is referenced by our security.txt file (RFC 9116) at https://www.yenerestaurant.com/.well-known/security.txt.
© 2026 Yene Restaurant · Operated by Repux Technologies PLC · Ethiopia