Security at GACS
This page is maintained by GACS — Global Anti-Crime & Safety to explain our security posture, platform-backed controls, responsible-disclosure scope, and how to reach the security team.
Platform-backed controls
GACS runs on Lovable Cloud. Lovable's project settings list platform compliance and security controls including SOC 2 Type II, GDPR, and ISO 27001. That matters for trust, but it is not the same as GACS holding its own separate SOC 2 or ISO 27001 audit report. We describe these as platform/provider controls and keep GACS-owned claims separate.
Contact
- Email: security@gacs.app
- Machine-readable: /.well-known/security.txt
- Acknowledgment SLA: within 48 hours · Triage SLA: 5 business days
Scope
In scope
- gacs.app web app and APIs
- Authentication and account flows
- Public dataset endpoints (/api/public/*)
- Scam report submission pipeline
Out of scope
- Third-party platform and payment providers
- Social engineering against staff or users
- DoS / volumetric testing
- Self-XSS and missing best-practice headers without impact
Safe harbor
Good-faith security research conducted under this policy will not result in legal action from GACS. Please don't access other users' data, don't run destructive tests against production, and give us a reasonable window to ship a fix before public disclosure.
FAQ
How do I report a security vulnerability in gacs.app?
Email security@gacs.app with reproduction steps. We acknowledge within 48 hours and aim to triage within 5 business days. See our machine-readable security.txt at /.well-known/security.txt.
Does GACS run a paid bug bounty?
Not at this time. We publicly credit responsible reporters on this page and on /trust when they want attribution.
What is in scope?
Anything served from gacs.app — including the web app, public API endpoints, authentication, and the report submission pipeline. Out of scope: third-party platform providers, payment providers, social-engineering, and DoS testing.
Will you take legal action against good-faith researchers?
No. Researchers acting in good faith under this policy will not face legal action from GACS. Don't access other users' data, don't run destructive tests against production, and don't publish details before we've shipped a fix.
Does GACS handle payments or private keys?
No. GACS never takes payments, never executes trades, and never asks users for seed phrases or private keys. Anyone claiming otherwise in our name is impersonating us — please report it.
More about how we operate: methodology · editorial policy · trust.
Authoritative sources
Independent primary sources used to check and corroborate the guidance on this page.
- FBI Internet Crime Complaint Center (IC3)
Official US channel for reporting internet-enabled fraud and cybercrime.
- US Federal Trade Commission — ReportFraud
Consumer fraud reporting and published enforcement data.
- UK Action Fraud
UK national reporting centre for fraud and cybercrime.
- Canadian Anti-Fraud Centre
Canada's central repository for fraud reports and scam alerts.
