MTNGH 2.16 ▲ 0.3% GCB 6.35 ▼ 2.5% ETI 0.34 ▲ 0.4% CAL 0.38 ▲ 1.0% GOIL 1.63 ▼ 1.2% SIC 0.71 ▲ 0.1% EGH 8.75 ▼ 2.4% ACCESS 4.00 ▲ 2.7% SOGEGH 1.87 ▼ 2.5% FML 4.28 ▼ 1.5% EGL 3.23 ▼ 0.3% GGBL 3.15 ▲ 2.6% SCB 18.94 ▲ 0.0% UNIL 10.45 ▲ 2.7% TOTAL 14.87 ▲ 1.7% BOPP 22.33 ▲ 2.8% MTNGH 2.16 ▲ 0.3% GCB 6.35 ▼ 2.5% ETI 0.34 ▲ 0.4% CAL 0.38 ▲ 1.0% GOIL 1.63 ▼ 1.2% SIC 0.71 ▲ 0.1% EGH 8.75 ▼ 2.4% ACCESS 4.00 ▲ 2.7% SOGEGH 1.87 ▼ 2.5% FML 4.28 ▼ 1.5% EGL 3.23 ▼ 0.3% GGBL 3.15 ▲ 2.6% SCB 18.94 ▲ 0.0% UNIL 10.45 ▲ 2.7% TOTAL 14.87 ▲ 1.7% BOPP 22.33 ▲ 2.8%
Responsible disclosure

Vulnerability Disclosure Policy

The security of our platform and our customers' financial data is our top priority. We welcome good-faith reports from security researchers and will work with you to verify and fix any issue.

Report a vulnerability arrow_forward
check_circle

In scope

  • All *.cdhsecurities.com web domains and subdomains
  • The CDH Securities investor web app and admin portal
  • CDH Securities mobile applications (iOS & Android)
  • Public CDH Securities APIs and services
cancel

Out of scope

  • Physical attacks against offices, staff or hardware
  • Social engineering of staff, customers or partners
  • Denial-of-service (DoS/DDoS) and volumetric/load testing
  • Phishing or spam, and automated scanner output without a working exploit
  • Self-XSS, missing security headers or missing CAPTCHA without a demonstrated impact
  • Clickjacking on pages with no sensitive action
  • Issues requiring physical access to a victim's unlocked device
  • Best-practice suggestions without an exploitable vulnerability

How to report

Email your findings to security@cdhsecurities.com. Please include:

  • arrow_rightA clear description of the vulnerability
  • arrow_rightStep-by-step reproduction instructions
  • arrow_rightAffected URLs, endpoints or screens
  • arrow_rightProof-of-concept (code, requests or screenshots)
  • arrow_rightThe potential impact
  • arrow_rightYour preferred contact details

Please do

  • checkTest only accounts you own or are explicitly authorised to test
  • checkStop and report immediately if you access another user's data
  • checkKeep findings confidential until we confirm they are resolved
  • checkGive us reasonable time to remediate before any public disclosure

Please don't

  • closeAccess, modify, download or delete data that isn't yours
  • closeDegrade, interrupt or damage our systems or services
  • closeViolate the privacy of our customers or staff
  • closeUse findings for extortion or any unlawful purpose

What to expect

Within 48 hours

We acknowledge receipt of your report.

Within 5 business days

We complete an initial assessment and triage severity.

Ongoing

We keep you updated through remediation.

On resolution

We confirm the fix and, with your permission, credit you.

Safe harbour & recognition

We do not currently run a paid bug-bounty programme. However, if you make a good-faith effort to follow this policy, we will not pursue or support legal action against you, and we are happy to publicly credit you (with your permission) for valid, responsibly disclosed reports. Please act in good faith, avoid privacy violations and data destruction, and give us reasonable time to remediate.

Onboarding open · Ghana

Start earning the
treasury rate today.

Open an account in under two minutes. KYC by Ghana Card, fund via MoMo or bank, earn from your first cedi.

Min ticket
GH₵10
Onboard
< 2 min
Up to
11.59%