Security & official messages
Know when it is really Yellow Yellow.
Use this page to verify our public channels, recognise common scams and report a security concern without taking unnecessary risks.
Verify a message
Check the full address, not only the sender's display name.
Company email ends in @yellowyellowmobility.com. Our public websites are www.rideyellowyellow.com and www.yellowyellowmobility.com.
- Open our website by typing the address yourself or using a trusted bookmark. Do not rely on a link inside an unexpected message.
- A familiar name or logo is not proof. Expand the sender details and inspect the full email address.
- Unexpected urgency, secrecy, payment changes, attachments or requests to move a conversation away from official channels are warning signs.
- Recruitment messages use an official company address. Yellow Yellow does not charge application, interview, placement or onboarding fees.
Protected information
Yellow Yellow will never ask for these secrets by email, chat or social media.
- Your password, OTP, recovery code or authentication-app code.
- Your MoMo PIN, card PIN, full card details or banking password.
- API keys, administrator keys, device unlock codes or remote access to your phone or computer.
- Payment to a staff member's personal number as a condition for a ride, job, driver approval or owner approval.
Official support may ask for limited information needed to locate a case, but it will not ask you to disclose a secret that can sign in, approve a payment or take control of an account.
Report a concern
Stop, preserve the evidence and tell us through a separate channel.
- Do not reply, click a link, open an attachment, scan a QR code or call a number supplied in the suspicious message.
- Take a screenshot showing the full sender address, subject and time. Preserve the original message and headers where possible.
- Email security@yellowyellowmobility.com from a separate new message. For ordinary service help, use support@yellowyellowmobility.com.
- If you already entered a password, OTP or payment secret, change the affected credential through the real provider immediately, sign out other sessions and contact the provider's fraud channel.
Do not post private trip, identity, payment or security evidence publicly.
Responsible disclosure
Help us fix a weakness without putting people or data at risk.
Send a concise report to security@yellowyellowmobility.com with the affected Yellow Yellow asset, steps to reproduce using test data, likely impact and any safely redacted evidence.
- Test only Yellow Yellow assets that we own and only in a non-destructive manner.
- Do not access another person's information, interrupt a ride, alter production data, test availability, collect credentials or socially engineer staff or users.
- Do not test Namecheap, Supabase, Google, Apple, Expo, Paystack, Arkesel or another provider without that provider's written permission.
- Stop and report immediately if personal data, safety or service availability may be affected.
Yellow Yellow does not currently operate a public bug-bounty programme. A report does not create a right to payment, employment or permission for broader testing.
Security programme
Defence in layers, with accountable human decisions.
Yellow Yellow uses email authentication, multi-factor authentication, least-privilege access, protected secrets, secure mobile sessions, database access controls, audit records, website security policies, dependency and secret scanning, backups, incident procedures and controlled release checks.
Our Defensive Security and Assurance Agent performs authorised passive checks and prepares evidence-backed recommendations. Active production testing, staff simulations, provider-account testing, credential changes, public disclosure and risk acceptance always require a named human approval.
The machine-readable disclosure contact is available at /.well-known/security.txt.