Skip to content
Security

Reporting a security issue.

If you have found a weakness in something GSS runs, we want to know about it. This page explains what that covers and how to write it up.

Found a critical vulnerability? Email [email protected] immediately. Do not share or publish details before we have resolved the issue.

Helping us stay secure.

GSS operates a responsible disclosure programme open to any security researcher who discovers a genuine vulnerability in our systems. We are committed to working with the security community to protect our customers. In exchange, we commit to responding promptly, keeping you informed, and rewarding valid, in-scope submissions.

Scope

What GSS runs.

The surfaces below are in scope for the programme. Findings against anything else are outside it — including denial-of-service testing, physical or social-engineering attacks, third-party services we do not control, and unvalidated scanner output.

  1. This website

    The public site — its pages, its static assets and anything served from it.

  2. The client portal

    The separate application where customers sign in and manage their accounts.

  3. Sign-in and account access

    Authentication, second factors, session handling and account recovery.

  4. Payment and card flows

    Anything that moves money or changes a card control, including the checks around it.

Describing what you found.

How we classify what you find. The severity we agree with you determines the reward band, and the bands are listed with the reporting channel below.

Critical
Remote code execution, a full authentication bypass, taking over an account, or anything that moves money without authorisation.
High
Privilege escalation, reaching another customer’s records, or stored script injection with real consequences.
Medium
Reflected script injection, cross-site request forgery on an action that matters, or limited access to data that is not sensitive.
Low
Missing security headers, over-detailed error messages, open redirects with little consequence.

Before you send anything.

  1. Write it down properly

    Steps to reproduce, the component affected, and what someone could actually do with it. A proof of concept helps; a scanner’s output on its own does not.

  2. Stop at proof

    Show the problem exists and go no further. If you reach anyone’s data, stop immediately and say so in your report.

  3. Keep it private

    Do not publish, post or share the details until the issue is resolved. That is the part that protects customers.

  4. Send it to us

    Email [email protected] with the full write-up. Encrypt it with our PGP key if it contains credentials, an exploit or customer data.

Rules of engagement

How to go about it.

Follow these and you are acting inside the programme. Test only what you own, stop at proof, and give us reasonable time to fix an issue before you discuss it publicly.

Please do

  • Test only against accounts and data that are your own
  • Stop the moment you reach anybody else’s information
  • Give enough detail for someone else to reproduce the issue
  • Describe the impact plainly, without overstating it
  • Allow time for a fix before saying anything publicly

Please do not

  • Go further into a system than proving the issue requires
  • Read, change or delete anybody else’s data
  • Run automated scanners against live systems
  • Attempt social engineering or phishing against staff or customers
  • Make payment a condition of staying quiet

How to report a vulnerability.

Email [email protected] with full details. Use PGP encryption for sensitive reports. Do not discuss the issue publicly before it is resolved. We acknowledge all reports within 24 hours and provide an initial severity assessment within 5 business days, and we will keep you informed at every stage.

The programme offers rewards for valid, in-scope submissions — up to €5,000 for critical findings, €2,000 for high, €500 for medium, and recognition for low-severity reports.

The programme states that GSS commits to responding promptly, keeping you informed, and rewarding valid, in-scope submissions.

[email protected]