dentz

Security

Security and vulnerability reporting

How we protect the information you trust us with, and what to do if you find a way around it.

A few company details are still being added.

This page describes accurately what our systems do with your information, but the highlighted details are outstanding and it has not yet been reviewed by a lawyer. If you need certainty before sending us anything, email hello@dentz.co.za and ask.

Last updated 29 September 2026. This page describes the safeguards we keep under section 19 of POPIA and our policy for reporting security weaknesses. It forms part of our terms of use.

01Our approach

Car owners trust us with photographs, phone numbers and where they live. Repair businesses trust us with their customers, their prices and their takings. We collect as little as a job needs, keep each business's records walled off from every other, and assume that anything we store could one day be targeted.

No system is perfectly secure, so this page also tells you how to report a weakness if you find one. We would much rather hear it from you.

02How we protect information

In transit and at rest

  • Every page, app and API call is served over HTTPS. Nothing travels unencrypted.
  • Our database and file storage providers encrypt stored data at rest.
  • Payment credentials a business connects, and saved card authorisations, are encrypted again by us (AES-256-GCM) before they are stored, with a key held apart from the database.
  • Card numbers never reach our systems. Payments are handled by Paystack, which is certified to the card industry's security standard (PCI DSS).

Who can see what

  • Every request to our backend is checked against who is asking. A repair business can only ever read or change its own records.
  • Inside a business, each person has a role, and the role decides what they can see and do. A technician does not see the books.
  • Our own staff cannot browse a business's data. To help with a support question, the business has to grant access. That access is read-only, expires after 30 minutes and is recorded.
  • Sensitive actions are written to an audit log that records who did what, and when.

Links, forms and integrations

  • Quote tracking links and invitation links are long random tokens. We store only a one-way hash of each, so a copy of our database would not reveal them.
  • Public forms, uploads, invitations and code entry are rate-limited, so they cannot be used to flood the system or to guess codes.
  • Messages from payment, email, chat and WhatsApp providers are only acted on if their signature checks out.
  • Error reports record the fault, not the person: there is no session or screen recording.

Who we rely on

We build on established providers rather than running our own servers. Each is listed, with what it does and where, in our privacy notice.

03Keeping your account safe

If you run a repair business on Dentz:

  • give each person their own login rather than sharing one, and remove people the day they leave
  • give each person the lowest role that lets them do their job
  • use a strong password you do not use anywhere else
  • treat a customer's tracking link like their phone number: send it to them, not to a group

We will never ask for your password, by email, WhatsApp or phone. If you get a message claiming to be us that asks for it, do not reply; forward it to security@dentz.co.za.

04If something goes wrong

If we find that personal information has been, or may have been, accessed or taken by someone without authority, we contain it first, then notify the Information Regulator and the people affected as soon as reasonably possible, as section 22 of POPIA requires.

Where the information belongs to a repair business's customers, we tell that business straight away and help it inform them.

05Reporting a vulnerability

If you believe you have found a security weakness in Dentz, please tell us privately first. Email:

A useful report includes:

  • what the weakness is, and where (the page, address or app screen)
  • the steps to reproduce it, with screenshots or a short video if that helps
  • what an attacker could do with it
  • how to reach you, and whether you would like to be credited

Reports in English are easiest for us. You do not need a working exploit: a clear description is enough.

06What you can expect from us

WhenWhat we do
Within 3 business daysConfirm we have your report and who is handling it
Within 10 business daysTell you whether we can reproduce it and how serious we think it is
Until it is fixedKeep you updated, and tell you when the fix is live

We aim to fix critical issues within 30 days, and others as quickly as their severity warrants. With your permission, we will thank you by name once the fix is out. We do not currently run a paid bug bounty.

07Testing in good faith

While looking into a possible weakness, please:

  • only test against accounts and data that are yours, or that you have been given permission to use
  • stop as soon as you reach anybody else's personal information, do not keep or share it, and tell us what you saw
  • never change or delete data that is not yours
  • not degrade the service for others: no denial-of-service, spam or high-volume automated scanning
  • not use social engineering, phishing or physical attacks against our people, repairers or customers
  • give us reasonable time to fix the issue before you disclose it publicly; we suggest 90 days, and we will agree a date with you

Our commitment to you

If you follow this policy in good faith, we will treat your research as authorised by us, we will not take legal action against you or ask anyone else to, and we will work with you to understand and fix the problem. This commitment covers only Dentz systems; we cannot give permission on behalf of the providers we use.

08What is in scope

Website
dentz.co.za and its pages
Portal and console
The repairer portal and staff console, on *.dentz.co.za
Mobile app
The Dentz app for technicians and owners
Our backend
The APIs these apps call

Not in scope: the services of the providers we use (report those to them directly), and findings with no demonstrated security impact, such as:

  • reports produced by an automated scanner without a working proof
  • missing security headers or cookie flags on their own
  • clickjacking on pages with no sensitive action
  • self-XSS, or anything that requires the victim to paste code into their own browser
  • account or email enumeration on public forms
  • denial-of-service or volume-based attacks

09Contact

Security reports
security@dentz.co.za
Privacy questions
Emile Boshoff, privacy@dentz.co.za
Free quote from a photoUsually a call back the same day
Snap a dent