Africoders Works

Trust

Security at Africoders Works

Last updated: 30 July 2026

How we approach security for the Works website and enquiry systems. This is an operational overview—not a certification claim.

Report an issue

Email enough detail for us to reproduce the issue. Avoid accessing data that is not yours.

hello@africoders.com

Africoders Network Limited (RC 1404892) operates Africoders Works. We do not list invented ISO, SOC, or similar certifications on this page.

Operational practices

These controls apply to the Africoders Works public site and lead/enquiry systems.

  • Secure transport

    HTTPS for the public Africoders Works site.

  • Form and session protection

    CSRF protection and hardened session handling on enquiry forms.

  • Abuse prevention

    Rate limiting on contact, project, and training endpoints. Optional Turnstile when configured.

  • Access control

    Role-restricted staff access to leads, applications, and attachments.

  • Safe uploads

    Type and size limits for enquiry attachments stored privately.

  • Operational monitoring

    Queued mail events, audit logs for lead actions, and production process supervision.

How security responsibility is divided

1 · Africoders.net

Works site & enquiries

Public marketing, training interest, and project lead intake for Africoders Works.

2 · Client delivery

Project security

Environments, secrets, and vulnerability handling for contracted work are defined in agreements—not implied here.

3 · Africoders.com

Community platform

A separate product surface. Community-only issues should use reporting channels on that domain.

Client project security

Security expectations for contracted delivery work are defined in project agreements and technical design. Marketing copy on this site does not expand those obligations.

Responsible disclosure

How to report

  • Email hello@africoders.com with steps to reproduce.
  • Include affected URL, browser or tool versions, and screenshots where helpful.
  • Do not access, modify, or exfiltrate data that is not yours.
  • Give us a reasonable window to investigate before public disclosure.

We do not publish a guaranteed response SLA on this page.