Security

How we protect
your account and data.

SharpCut never holds your money — but it does hold your phone number, your prediction history and your payment reference, and those deserve to be looked after properly.

  • security@sharpcut.ng
  • 24-hour acknowledgement
  • 90-day disclosure window

What we hold, and what we don't

The most important security property of SharpCut is architectural: we are not a bookmaker. There is no wallet, no balance, no withdrawal flow and no stored card. Payments run through Paystack, which holds the card data under PCI-DSS; we keep only a transaction reference and a subscription status. An attacker who fully compromised a SharpCut account would find a betting history and a phone number — not money.

Controls in place

  • Transport security. TLS 1.3 everywhere, HSTS with preload, and no plaintext fallback.
  • Content Security Policy. A strict CSP with no inline script execution, blocking the most common route to session theft.
  • Authentication. Phone-based sign-in with one-time codes; codes expire in 10 minutes and are rate-limited per number and per IP.
  • Encryption at rest. Database and object storage encrypted with managed keys; backups encrypted and access-logged.
  • Least privilege. Production data access is role-scoped, time-boxed and logged. No engineer holds standing production credentials.
  • Dependency hygiene. Automated vulnerability scanning on every build, with a 7-day SLA on high-severity advisories.
  • Payments. Card details never touch our servers. Paystack handles collection, tokenisation and storage.

Reporting a vulnerability

Email security@sharpcut.ng with enough detail to reproduce the issue. Our machine-readable policy lives at /.well-known/security.txt.

  • We acknowledge every report within 24 hours.
  • We aim to confirm or dismiss within 5 business days, with a remediation plan attached.
  • We ask for 90 days before public disclosure, and we'll tell you honestly if we need longer.
  • We don't yet run a paid bounty. We do credit every valid reporter who wants credit.

Please don't

  • Run automated scanners against production hard enough to degrade service for real users.
  • Access, modify or exfiltrate any account that isn't yours. If you stumble into someone's data, stop and tell us.
  • Use social engineering against our staff or our providers.
  • Test physical security or anything belonging to Paystack, our data providers, or our hosting vendor.

Stay inside those lines and we will not pursue any legal action over your research — that commitment is deliberate and we'll honour it.

Protecting your own account

  • Nobody at SharpCut will ever ask for your one-time code. Not support, not on WhatsApp, not ever. Anyone who does is committing fraud.
  • We will never ask you to send money, fund a wallet, or “activate” a subscription by transfer to a personal account. All payment happens through Paystack inside the app.
  • Our only channels are sharpcut.ng and email addresses ending @sharpcut.ng. Treat anything else as fake.
  • If you think your account is compromised, email support@sharpcut.ng and we'll invalidate every session on it.