RESPONSIBLE DISCLOSURE POLICY

Denaee is committed to maintaining the highest standards of security across its fintech and super app platforms. We recognise the valuable role ethical security researchers play in identifying potential vulnerabilities, and we encourage responsible disclosure to ensure the continued safety of our systems and user data. Our Responsible Disclosure Policy provides clear guidelines on how security professionals can report vulnerabilities in a structured and ethical manner. We request that all security research be conducted in good faith, avoiding disruption to services, unauthorised data access, or any actions that could compromise the integrity of our systems. Reports should include sufficient details, such as proof of concept and potential impact, to help our security team assess and address the issue effectively.
Denaee takes all reports seriously and follows a structured process to validate, prioritise, and resolve vulnerabilities. While we do not operate a formal bug bounty programme, we may acknowledge significant contributions at our discretion. Ethical researchers who comply with this policy will be protected from legal repercussions, provided they act responsibly and within legal boundaries. Our security team is committed to engaging openly with the cybersecurity community and continuously improving our security measures. We encourage all researchers to report vulnerabilities via our dedicated security email, and we appreciate their cooperation in keeping our digital ecosystem secure for all users.
Shan Nwe— CEO Denaee
Denaee Responsible Disclosure Policy
At Denaee, we are committed to maintaining the highest standards of security for our customers, partners, and employees. Protecting our digital platforms, financial systems, and customer data is a top priority. We recognise the invaluable role that ethical security researchers, security professionals, and members of the public play in identifying and reporting potential vulnerabilities within our systems. This Responsible Disclosure Policy outlines how vulnerabilities should be reported and the expectations we set for responsible disclosure.
Commitment to Security and Transparency
Denaee takes cybersecurity seriously and has robust security measures in place to safeguard our infrastructure, applications, and data. Despite these efforts, we acknowledge that no system is completely immune to vulnerabilities.
To further enhance our security framework, we encourage responsible disclosure of any security weaknesses that may be discovered within our systems.
We believe in a transparent and cooperative approach to security and will work closely with security researchers to address identified vulnerabilities promptly and effectively. Our aim is to protect our users while fostering a collaborative relationship with the security community.
Scope of the Responsible Disclosure Policy
This policy applies to all digital services provided by Denaee, including but not limited to:
• Denaee’s super app and fintech platforms
• Web-based platforms and mobile applications
• APIs and payment processing systems
• Internal administrative portals and third-party integrations
We encourage responsible reporting of vulnerabilities that may pose a risk to the confidentiality, integrity, or availability of our systems. However, this policy does not apply to issues such as:
• Outdated software versions that are no longer in use or actively maintained
• General best practice recommendations rather than exploitable security vulnerabilities
• Reports based on automated scans without a clear proof of concept
• Social engineering attacks targeting Denaee employees, customers, or partners
Guidelines for Responsible Disclosure
To ensure an ethical and constructive approach to vulnerability disclosure, we request that all reports adhere to the following guidelines:
• Act in Good Faith: Any security research conducted on Denaee’s systems should be done in a responsible and ethical manner, with no intent to disrupt services, steal data, or cause harm to users.
• Provide Sufficient Details: Reports should include a clear and concise description of the vulnerability, steps to reproduce it, potential impact, and any suggested remediation. Proof of concept (PoC) examples or screenshots can significantly aid in the resolution process.
• Avoid Data Exposure: Researchers should not access, modify, store, or share any sensitive customer data as part of their research. If any data is inadvertently accessed, it must be immediately reported and not disclosed further.
• No Service Disruptions: Any testing should avoid activities that could cause service interruptions, system degradation, or unauthorised access to customer accounts.
• Comply with Applicable Laws: All vulnerability research must comply with relevant laws and regulations. Unauthorised access, data theft, or malicious intent will be considered a breach of this policy.
How to Report a Security Vulnerability
If you believe you have discovered a vulnerability within Denaee’s systems, we encourage you to report it to us as soon as possible through the following process:
1. Submit a Report: Contact Denaee’s security team via our designated security disclosure email, hello@denaee.com. Include all necessary details to help us assess the risk.
2. Acknowledge Receipt: Our security team will acknowledge the report within three business days and may request further information for investigation.

3. Assessment and Resolution: We will prioritise and validate reports based on their severity. Vulnerabilities will be addressed in accordance with our internal security protocols.
4. Responsible Communication: We request that researchers do not publicly disclose the vulnerability until we have had the opportunity to mitigate the issue. We will coordinate an appropriate disclosure timeline where necessary.
5. Recognition and Collaboration: Denaee values ethical security contributions. While we do not operate a formal bug bounty programme, we may, at our discretion, provide recognition for significant findings that contribute to our platform’s security.
Safe Harbour and Protection for Ethical Researchers
Denaee supports ethical security research and aims to protect well-intentioned individuals who comply with this policy. As long as security researchers act in good faith and within the guidelines of responsible disclosure, we will:
• Not initiate legal action against researchers who comply with this policy
• Engage openly and transparently with the security community
• Recognise significant contributions through public acknowledgements (if agreed upon by both parties)
However, failure to follow responsible disclosure guidelines, unauthorised data access, or activities that intentionally harm Denaee’s systems or users may result in legal consequences.
Commitment to Continuous Security Improvement
Denaee remains dedicated to strengthening its security posture through continuous monitoring, internal audits, and collaboration with the security research community. Responsible disclosure plays a vital role in our proactive security strategy, ensuring that our fintech platforms and super app services remain secure, trustworthy, and resilient.
We appreciate the efforts of ethical security researchers and welcome constructive collaboration in our ongoing mission to safeguard user data and digital services. Should you have any security concerns or discoveries, we encourage you to report them in line with this policy.
For any further queries regarding responsible disclosure, please contact our security team at hello@denaee.com.
- Shan Nwe (CEO)

Denaee takes its Responsible Disclosure Policy seriously and is dedicated to fostering a secure and transparent environment for ethical security research. We actively encourage responsible vulnerability reporting to help strengthen our platform’s defences and protect user data. Our security team diligently reviews all reports, swiftly addressing any identified risks while ensuring open collaboration with the cybersecurity community. By prioritising responsible disclosure, we uphold the highest standards of security, demonstrating our unwavering commitment to safeguarding our systems and maintaining the trust of our users.
Created
22/09/2019
Version
V.1.3
V.1.3 Date
05/01/2025
By
Shan Nwe
Project
Denaee
Type
Fintech
Wrote
22/09/19
Version
V.1.3
V.1.3 Date
05/01/26
By
Shan Nwe
Project
Denaee
Type
Fintech