Safety & security

Cyber Security

How we protect accounts, data and payments, and how to report a security vulnerability.

Last updated

Keeping your account, your data and your payments secure is central to earning your trust. This page explains how we protect BaduAds.com, what you can do to protect your account, and how to report a security issue to us.

How we protect the platform

  • Encryption in transit. BaduAds.com is served over HTTPS, so data between your device and our servers is encrypted.
  • Password protection. Passwords are stored only as one-way hashes. We cannot see your password, and our staff will never ask for it.
  • Abuse prevention. Sign-up, login, password reset and contact forms use bot protection and limit repeated attempts to slow down password guessing and spam.
  • Payments. Card payments for plans and promotions are handled by PayHere's secure checkout. Card details are entered on PayHere's page, and we never receive or store your full card number.
  • Limited access. Access to administration tools is role-based and restricted to authorised staff who need it for their work.
  • Secure development. We protect against common web attacks such as cross-site request forgery and review changes before they go live.

Your personal data is handled in line with our Privacy Policy and the Personal Data Protection Act, No. 9 of 2022.

Protect your account

  • Use a strong password that you don't use on any other website.
  • Never share your password or one-time passwords (OTPs) with anyone, including someone claiming to be from BaduAds.com.
  • Check the address bar: our website is baduads.com. Be suspicious of links in messages that ask you to log in.
  • Log out on shared or public devices, and keep your phone and browser updated.
  • If you think someone else has accessed your account, change your password immediately and contact us.

Report a security vulnerability

If you believe you've found a security vulnerability in BaduAds.com, please tell us privately so we can fix it before it is exploited. Email support@baduads.com with the subject line "Security vulnerability report" and include:

  • a description of the issue and its potential impact;
  • the affected page or URL, and steps to reproduce it;
  • any proof-of-concept, screenshots or logs that help us understand it.

What we ask of you

  • Only test against your own accounts, and stop as soon as you've confirmed the issue.
  • Don't access, change or delete other users' data, and don't keep any data you come across.
  • No denial-of-service testing, spam, social engineering or physical attacks.
  • Give us reasonable time to fix the issue before telling anyone else about it.

What you can expect from us

  • We acknowledge reports, normally within five working days, and keep you informed of our progress.
  • We won't take legal action against researchers who report in good faith and follow these guidelines.
  • With your permission, we're happy to credit you once the issue is fixed.

We don't currently run a paid bug bounty programme. Reports about spam, scam listings or account problems should go through our Safety & Security guidance or contact page.

Related