1. Our security commitment
RIC Development Botswana recognises that website security is essential to protecting customers, employees, business information and the reputation of Sarona City.
We apply proportionate technical and organisational safeguards and review them as the website, technology and threat environment change.
Security is treated as an ongoing process of prevention, monitoring, review and improvement.
2. Secure connections
Sarona City uses HTTPS to encrypt information exchanged between supported browsers and the website.
HTTP Strict Transport Security instructs compatible browsers to use secure connections and helps reduce the risk of protocol-downgrade attacks.
3. Browser security protections
The website applies browser security policies designed to reduce common web risks, including:
- Content Security Policy controls for approved content sources
- Clickjacking protection
- MIME-type sniffing protection
- Referrer-information restrictions
- Restrictions on unnecessary browser features such as camera and microphone access
- Cross-origin isolation and resource policies
4. Session and cookie security
Website sessions use a host-restricted cookie with Secure, HttpOnly and SameSite protections.
Session controls are designed to reduce the risk of unauthorised session reuse, browser-script access and cross-site request attacks.
Further details are available in our Cookie Policy .
5. Application and form security
Safeguards applied to website forms and application functions include:
- Cross-site request forgery tokens
- Server-side input validation
- Output encoding
- Prepared database statements
- Spam honeypot controls
- Submission rate controls
- Restricted HTTP request methods
- Suppression of technical errors from visitors
6. File and upload protection
Administrative upload functions restrict permitted file types and sizes. Upload locations are separated from application code and should not permit uploaded files to execute as server-side programs.
Uploaded content remains subject to validation, access restrictions and administrative review.
7. Administrative security
Administrative functionality is restricted to authorised users. Controls include authenticated sessions, protected routes, role-appropriate access and secure logout handling.
Administrative credentials must not be shared. Users should choose strong, unique passwords and report suspected compromise promptly.
8. Information protection
Access to stored enquiry and administrative information is limited according to operational requirements. Reasonable safeguards are used to reduce unauthorised access, alteration, disclosure and loss.
More information about personal-data handling is available in our Privacy Policy and the forthcoming Data Protection page.
9. Security limitations
No internet-based service can guarantee complete protection against against every threat. We therefore continue reviewing controls, applying updates and responding to identified risks.
Visitors should avoid sending passwords, banking credentials or identity documents through the general enquiry form.
10. Report a security concern
If you believe you have identified a security issue affecting the Sarona City website, please report it responsibly. Include enough information for us to understand and reproduce the concern.
Please do not:
- Access, alter or download other people’s data
- Disrupt website availability or performance
- Use automated destructive testing
- Publish sensitive details before we investigate
- Use a security concern for extortion or fraud