How we protect
your account and data.
SharpCut never holds your money — but it does hold your phone number, your prediction history and your payment reference, and those deserve to be looked after properly.
What we hold, and what we don't
The most important security property of SharpCut is architectural: we are not a bookmaker. There is no wallet, no balance, no withdrawal flow and no stored card. Payments run through Paystack, which holds the card data under PCI-DSS; we keep only a transaction reference and a subscription status. An attacker who fully compromised a SharpCut account would find a betting history and a phone number — not money.
Controls in place
- Transport security. TLS 1.3 everywhere, HSTS with preload, and no plaintext fallback.
- Content Security Policy. A strict CSP with no inline script execution, blocking the most common route to session theft.
- Authentication. Phone-based sign-in with one-time codes; codes expire in 10 minutes and are rate-limited per number and per IP.
- Encryption at rest. Database and object storage encrypted with managed keys; backups encrypted and access-logged.
- Least privilege. Production data access is role-scoped, time-boxed and logged. No engineer holds standing production credentials.
- Dependency hygiene. Automated vulnerability scanning on every build, with a 7-day SLA on high-severity advisories.
- Payments. Card details never touch our servers. Paystack handles collection, tokenisation and storage.
Reporting a vulnerability
Email security@sharpcut.ng with enough detail to reproduce the issue. Our machine-readable policy lives at /.well-known/security.txt.
- We acknowledge every report within 24 hours.
- We aim to confirm or dismiss within 5 business days, with a remediation plan attached.
- We ask for 90 days before public disclosure, and we'll tell you honestly if we need longer.
- We don't yet run a paid bounty. We do credit every valid reporter who wants credit.
Please don't
- Run automated scanners against production hard enough to degrade service for real users.
- Access, modify or exfiltrate any account that isn't yours. If you stumble into someone's data, stop and tell us.
- Use social engineering against our staff or our providers.
- Test physical security or anything belonging to Paystack, our data providers, or our hosting vendor.
Stay inside those lines and we will not pursue any legal action over your research — that commitment is deliberate and we'll honour it.
Protecting your own account
- Nobody at SharpCut will ever ask for your one-time code. Not support, not on WhatsApp, not ever. Anyone who does is committing fraud.
- We will never ask you to send money, fund a wallet, or “activate” a subscription by transfer to a personal account. All payment happens through Paystack inside the app.
- Our only channels are
sharpcut.ngand email addresses ending@sharpcut.ng. Treat anything else as fake. - If you think your account is compromised, email support@sharpcut.ng and we'll invalidate every session on it.