Security
Responsible Disclosure
How to report a security vulnerability to GSCORA. We welcome reports from security researchers.
In scope
- Web applications and APIs on gscora.com, studio.gscora.com, and api.gscora.com
- Legacy domains during the transition (corporate.genstudioai.ai, genstudioai.ai, api.genstudioai.ai)
- Authentication/authorization, data handling, injection, and information-disclosure vulnerabilities
Out of scope
- DoS/DDoS, physical attacks, and social engineering
- Configuration suggestions with no impact, and reports based solely on known-vulnerability scanners
How to report
Email contact@gscora.com with reproduction steps and impact.
Response targets
| First acknowledgment | within 3 business days |
|---|---|
| Triage | within 10 business days |
| Fix / coordinated disclosure | agreed per severity |
Please keep the report confidential until it is fixed. We will not pursue legal action against good-faith reporters who act within our Terms.
Security questions? Contact us