Skip to main content
GACS will never ask for your seed phrase, private keys, or payment. Always free.
Responsible disclosure

Security at GACS

This page is maintained by GACS — Global Anti-Crime & Safety to explain our security posture, platform-backed controls, responsible-disclosure scope, and how to reach the security team.

Platform-backed controls

GACS runs on Lovable Cloud. Lovable's project settings list platform compliance and security controls including SOC 2 Type II, GDPR, and ISO 27001. That matters for trust, but it is not the same as GACS holding its own separate SOC 2 or ISO 27001 audit report. We describe these as platform/provider controls and keep GACS-owned claims separate.

SOC 2 Type II platform controlGDPR-aligned platform controlISO 27001 platform control

Contact

Scope

In scope

  • gacs.app web app and APIs
  • Authentication and account flows
  • Public dataset endpoints (/api/public/*)
  • Scam report submission pipeline

Out of scope

  • Third-party platform and payment providers
  • Social engineering against staff or users
  • DoS / volumetric testing
  • Self-XSS and missing best-practice headers without impact

Safe harbor

Good-faith security research conducted under this policy will not result in legal action from GACS. Please don't access other users' data, don't run destructive tests against production, and give us a reasonable window to ship a fix before public disclosure.

FAQ

How do I report a security vulnerability in gacs.app?

Email security@gacs.app with reproduction steps. We acknowledge within 48 hours and aim to triage within 5 business days. See our machine-readable security.txt at /.well-known/security.txt.

Does GACS run a paid bug bounty?

Not at this time. We publicly credit responsible reporters on this page and on /trust when they want attribution.

What is in scope?

Anything served from gacs.app — including the web app, public API endpoints, authentication, and the report submission pipeline. Out of scope: third-party platform providers, payment providers, social-engineering, and DoS testing.

Will you take legal action against good-faith researchers?

No. Researchers acting in good faith under this policy will not face legal action from GACS. Don't access other users' data, don't run destructive tests against production, and don't publish details before we've shipped a fix.

Does GACS handle payments or private keys?

No. GACS never takes payments, never executes trades, and never asks users for seed phrases or private keys. Anyone claiming otherwise in our name is impersonating us — please report it.

More about how we operate: methodology · editorial policy · trust.

Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team · Updated July 22, 2026

Cite this page: GACS (2026). Security — GACS. https://gacs.app/security · Record ID GACS-security

Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.