Security Disclosure (Vulnerability Disclosure Policy) — GAO Internet
Effective date: Jan 1, 2026
Last Updated: Jan 1, 2026
We take security seriously and welcome good-faith vulnerability reports to help keep GAO Internet safe.
1. Scope
This policy applies to security vulnerabilities affecting:
Third-party services (blockchains, wallets, dApps, external providers) are out of scope unless the vulnerability is in our integration code.
2. How to report
Email: security@gao.systems
Please include:
If you require encrypted communication, request our PGP key.
3. Safe harbor for good-faith research
We will not pursue legal action for good-faith research that:
4. Coordinated disclosure
5. Out of scope (examples)
6. Security contact and incident reporting
For suspected active exploitation: security@gao.systems
General support: support@gao.systems
7. security.txt (Recommended)
You may publish the following file at:
/.well-known/security.txt
Contact: mailto:security@gao.systems
Contact: mailto:support@gao.systems
Policy: https://gao.systems/security-disclosure
Preferred-Languages: en, vi
Canonical: https://gao.systems/.well-known/security.txt