Security Vulnerability Disclosure Policy

Our Commitment to Security

Gecko Alliance is committed to protecting the security of our products, our online services, and our customers’ information. If you believe you’ve identified a security vulnerability affecting one of our products or services, we want to know about it, and we’re committed to working with you to understand and address it responsibly.

Please note: Gecko Alliance does not operate a bug bounty program and does not offer monetary rewards or compensation for vulnerability reports.

Scope

This policy applies to our connected products, mobile application, and the online services that support them. It does not cover:

  • Social engineering or phishing attempts directed at Gecko Alliance staff

  • Physical attacks against our staff or facilities

  • Denial-of-service testing against our products or systems

  • Services or products not offered directly by Gecko Alliance

  • Any other activity intended for malicious purposes rather than good-faith security research

Responsible Disclosure

If you come across a potential vulnerability while acting in good faith and within the scope above, we ask that you:

  • Stop at the point where you can demonstrate the issue, and avoid going further than necessary to confirm it.

  • Avoid accessing, modifying, downloading, or deleting data that isn’t yours.

  • Avoid any action that could degrade or disrupt our services for other users.

  • Report it to us promptly rather than continuing to explore it further.

  • Keep the details of any vulnerability confidential until we’ve confirmed it’s resolved, or authorized disclosure in writing.

If, in the course of identifying an issue, you encounter personal, financial, or other sensitive data that isn’t yours, stop immediately, notify us, don’t share or retain that data, and delete any copies you may have made.

Provided you make a good-faith effort to follow these guidelines and stay within the scope above, we will not pursue legal action related to your research.

Reporting a Vulnerability

If you believe you’ve found a security vulnerability within this scope, please contact us at: infodataloi25@geckoal.com

To help us triage and respond quickly, please include:

  • When you identified the issue

  • The product, application, or service affected

  • Steps to reproduce the issue, and its potential impact

  • Any supporting details (screenshots, logs, proof-of-concept)

  • Any remediation suggestions you may have (optional)

What You Can Expect From Us

  • We will acknowledge your report within 5 business days.

  • For reports involving our connected products, we will provide regular updates until the issue is resolved.

  • We will let you know once the issue has been resolved, and, with your permission, are happy to credit you for the discovery.

Thank You

We appreciate the time and effort security researchers put into helping us improve our products. Thank you for practicing responsible disclosure.