Navigation
Type to search pages, tools, and sections…
Scope, safe-harbour, SLAs and recognition for good-faith security researchers.
In-scope: gacs.app and its subdomains, the /api/public/* surface, the Lovable-hosted backend that powers GACS, and our official browser extension. Out-of-scope: third-party services we integrate with (their vendors run their own programs), automated scanner output without proof of exploitability, social-engineering of GACS staff, denial-of-service, physical attacks, and findings on disposable preview URLs.
Email security@gacs.app with a clear PoC. PGP available on request. Please do not open public GitHub issues for security findings, do not post on social media before we have responded, and do not access more data than is necessary to demonstrate the issue.
GACS is an independent public-good project; we do not currently run a paid bounty. We do offer public credit on a hall-of-fame page, a verified researcher badge, and a free top-tier free certification (CFPS / CBI / OIA / MICA) for high-impact valid findings.
GACS will not pursue civil action or report you to law enforcement for good-faith security research that complies with this policy — even if you incidentally access data you should not have. You must stop immediately, report the issue, and delete any data you accessed.
Independent primary sources used to check and corroborate the guidance on this page.
Official US channel for reporting internet-enabled fraud and cybercrime.
Consumer fraud reporting and published enforcement data.
UK national reporting centre for fraud and cybercrime.
Canada's central repository for fraud reports and scam alerts.
Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team · Updated August 9, 2026
Cite this page: GACS (2026). Responsible Disclosure — GACS. https://gacs.app/responsible-disclosure · Record ID GACS-responsible-disclosure
Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.