Last updated 29 September 2026. This page describes the safeguards we keep under section 19 of POPIA and our policy for reporting security weaknesses. It forms part of our terms of use.
01Our approach
Car owners trust us with photographs, phone numbers and where they live. Repair businesses trust us with their customers, their prices and their takings. We collect as little as a job needs, keep each business's records walled off from every other, and assume that anything we store could one day be targeted.
No system is perfectly secure, so this page also tells you how to report a weakness if you find one. We would much rather hear it from you.
02How we protect information
In transit and at rest
- Every page, app and API call is served over HTTPS. Nothing travels unencrypted.
- Our database and file storage providers encrypt stored data at rest.
- Payment credentials a business connects, and saved card authorisations, are encrypted again by us (AES-256-GCM) before they are stored, with a key held apart from the database.
- Card numbers never reach our systems. Payments are handled by Paystack, which is certified to the card industry's security standard (PCI DSS).
Who can see what
- Every request to our backend is checked against who is asking. A repair business can only ever read or change its own records.
- Inside a business, each person has a role, and the role decides what they can see and do. A technician does not see the books.
- Our own staff cannot browse a business's data. To help with a support question, the business has to grant access. That access is read-only, expires after 30 minutes and is recorded.
- Sensitive actions are written to an audit log that records who did what, and when.
Links, forms and integrations
- Quote tracking links and invitation links are long random tokens. We store only a one-way hash of each, so a copy of our database would not reveal them.
- Public forms, uploads, invitations and code entry are rate-limited, so they cannot be used to flood the system or to guess codes.
- Messages from payment, email, chat and WhatsApp providers are only acted on if their signature checks out.
- Error reports record the fault, not the person: there is no session or screen recording.
Who we rely on
We build on established providers rather than running our own servers. Each is listed, with what it does and where, in our privacy notice.
03Keeping your account safe
If you run a repair business on Dentz:
- give each person their own login rather than sharing one, and remove people the day they leave
- give each person the lowest role that lets them do their job
- use a strong password you do not use anywhere else
- treat a customer's tracking link like their phone number: send it to them, not to a group
We will never ask for your password, by email, WhatsApp or phone. If you get a message claiming to be us that asks for it, do not reply; forward it to security@dentz.co.za.
04If something goes wrong
If we find that personal information has been, or may have been, accessed or taken by someone without authority, we contain it first, then notify the Information Regulator and the people affected as soon as reasonably possible, as section 22 of POPIA requires.
Where the information belongs to a repair business's customers, we tell that business straight away and help it inform them.
05Reporting a vulnerability
If you believe you have found a security weakness in Dentz, please tell us privately first. Email:
A useful report includes:
- what the weakness is, and where (the page, address or app screen)
- the steps to reproduce it, with screenshots or a short video if that helps
- what an attacker could do with it
- how to reach you, and whether you would like to be credited
Reports in English are easiest for us. You do not need a working exploit: a clear description is enough.
06What you can expect from us
We aim to fix critical issues within 30 days, and others as quickly as their severity warrants. With your permission, we will thank you by name once the fix is out. We do not currently run a paid bug bounty.
07Testing in good faith
While looking into a possible weakness, please:
- only test against accounts and data that are yours, or that you have been given permission to use
- stop as soon as you reach anybody else's personal information, do not keep or share it, and tell us what you saw
- never change or delete data that is not yours
- not degrade the service for others: no denial-of-service, spam or high-volume automated scanning
- not use social engineering, phishing or physical attacks against our people, repairers or customers
- give us reasonable time to fix the issue before you disclose it publicly; we suggest 90 days, and we will agree a date with you
08What is in scope
Not in scope: the services of the providers we use (report those to them directly), and findings with no demonstrated security impact, such as:
- reports produced by an automated scanner without a working proof
- missing security headers or cookie flags on their own
- clickjacking on pages with no sensitive action
- self-XSS, or anything that requires the victim to paste code into their own browser
- account or email enumeration on public forms
- denial-of-service or volume-based attacks