Security Disclosure (Vulnerability Disclosure Policy) — GAO Internet
Effective date: Jan 1, 2026
Last Updated: Jan 1, 2026
We take security seriously and welcome good-faith vulnerability reports to help keep GAO Internet safe.
1. Scope
This policy applies to security vulnerabilities affecting:
Third-party services (blockchains, wallets, dApps, external providers) are out of scope unless the vulnerability is in our integration code.
2. How to report
Email: [email protected]
Please include:
If you require encrypted communication, request our PGP key.
3. Safe harbor for good-faith research
We will not pursue legal action for good-faith research that:
4. Coordinated disclosure
5. Out of scope (examples)
6. Security contact and incident reporting
For suspected active exploitation: [email protected]
General support: [email protected]
7. security.txt (Recommended)
You may publish the following file at:
/.well-known/security.txt
Contact: mailto:[email protected]
Contact: mailto:[email protected]
Policy: https://gao.systems/security-disclosure
Preferred-Languages: en, vi
Canonical: https://gao.systems/.well-known/security.txt