Security

Responsible Disclosure

How to report a security vulnerability to GSCORA. We welcome reports from security researchers.

In scope

  • Web applications and APIs on gscora.com and genstudioai.ai
  • Authentication/authorization, data handling, injection, and information-disclosure vulnerabilities

Out of scope

  • DoS/DDoS, physical attacks, and social engineering
  • Configuration suggestions with no impact, and reports based solely on known-vulnerability scanners

How to report

Email security@gscora.com with reproduction steps and impact.

Response targets

Please keep the report confidential until it is fixed. We will not pursue legal action against good-faith reporters who act within our Terms.

Security questions? Contact us