Responsible Security Research

Security Disclosure Policy

We welcome ethical security researchers to help keep GT Microsystem safe. Learn about our vulnerability disclosure program and safe harbor terms.

Safe Harbor Commitment

GT Microsystem will not pursue legal action or law enforcement referrals against security researchers who conduct research in good faith, adhere to this policy, and report vulnerabilities responsibly.

Guidelines for Research

  • Do not access or modify data belonging to other users without explicit authorization.
  • Do not execute denial-of-service (DoS) attacks or degrade service performance.
  • Report vulnerabilities promptly to our team before making any public disclosure.
  • Give our engineering team reasonable time to patch the issue before publishing technical details.

Program Scope

In-Scope Assets

  • • *.gtmicrosystem.com
  • • Web & Mobile Apps
  • • Core REST/GraphQL APIs
  • • Smart Contracts & Ledger Nodes

Out-of-Scope

  • • Social Engineering / Phishing
  • • Physical Security Attacks
  • • Third-Party Partner Portals
  • • Spam / Volumetric DoS

PGP Encryption Fingerprint

Encrypt sensitive vulnerability submissions using our public PGP key:

4F92 A8C1 99B2 04E5 F812 77A4 1209 88E1 E83F 9920

Report a Vulnerability

Submit technical findings directly to our Security Operations Center.