Trust and safety
Portal security
What protects this site today, described without emphasis. Every measure listed here is in place; the ones we do not have are listed too.
Scope of this page
This page describes the public portal www.diaspora-cameroun.org: the information pages, the contact, membership and project submission forms, and the donation journey.
The member area is a separate application served under the same address. Its own security settings — password, active sessions — live inside each member's account and are not described here.
This page last checked :
What is in place
Most of these measures can be checked from your own browser, in the site's HTTP response headers.
The whole site is served over HTTPS
Every page and every call on this site goes through an encrypted connection. The site also asks browsers to refuse any unencrypted connection to this domain and its subdomains for two years (Strict-Transport-Security header).
A restrictive content policy
The browser may only load scripts, styles, images and fonts from this site itself, and may only submit forms back to this site. No third-party content, no iframe, no external plug-in is allowed — this is the main barrier against code being injected into a page.
This site cannot be framed by another
Displaying the portal inside an iframe is refused. That prevents a third-party site from laying a fake interface over the real one to make you click where you did not intend to.
Camera, microphone, location and payment disabled
The site tells the browser that none of its pages needs the camera, the microphone, geolocation, motion sensors or the browser payment interface. Those capabilities are therefore denied outright, even to a script that asked for them.
No bank card data passes through this site
The donation journey contains no card field: it redirects you to the payment page hosted by the provider, who alone handles that data. The portal stores no card number and holds no payment secret key.
Your email address is verified before a message is sent
The contact form sends a one-time code valid for ten minutes, limited to five attempts. The code itself is never kept: only its cryptographic fingerprint is stored, for the duration of the check.
Forms are rate-limited
Contact, membership, project submission and donor-area access requests are protected by a cap on submissions per hour. A blocked submission gets exactly the same answer as an accepted one, so that an automated script learns nothing.
Uploaded files are checked on the server
Project submissions accept a closed list of formats, with a per-file cap and an overall cap per submission. That check is enforced by the server, not only by the browser: it cannot be bypassed by editing the page.
No password is stored in clear text
Administration account passwords are put through a salted key-derivation function designed to resist brute force, and verification is done in constant time. The session is carried by a token that page scripts cannot read, and only its fingerprint is kept on the server.
Administrative actions are logged
Every action performed from the back office is written to an append-only log: who, what, when, on which item.
No tracker, no third-party cookie
The site only sets the cookies strictly necessary to its operation: no audience measurement, no advertising tracker, no cookie set by a third party. The detail is published in the cookie policy.
What we do not claim
A security page is judged as much on what it does not assert. None of the following exists today, and none is announced as if it did.
- No external security audit and no penetration test has been carried out on this portal.
- No security certification (ISO 27001, SOC 2 or equivalent) is held or being sought.
- No bug bounty programme is open: a report is welcome, but it is not paid for.
- No external availability monitoring is in place — the status published on the Service status page is measured from the server itself, and that limit is stated there.
- No guarantee of absolute security is given: the measures above reduce risk, they do not remove it.
Report a vulnerability
If you believe you have found a vulnerability on this site, write to us before discussing it publicly. We acknowledge every report.
- Describe the page or feature concerned and what you observed.
- Give the steps that reproduce the problem.
- Do not access data that is not yours, do not modify it and do not keep it.
- Do not run any test likely to degrade the service for other users.
We promise neither a fix deadline nor a reward: we promise an answer, and to tell you what was done.
Protecting yourself
Most fraud attempts aimed at an organisation like ours go around the site, through a fake message or a fake account. Three pages of this site speak directly to those situations.
