Vulnerability Disclosure

Last updated: July 13, 2026

We welcome good-faith security research. Report vulnerabilities to security@gtaup.com under this coordinated disclosure policy.

1. How to report

Email security@gtaup.com with a clear description of the issue, steps to reproduce, affected URLs or components, and your preferred contact method. Do not include real user data beyond what is necessary to demonstrate the issue.

Researchers can also discover this policy via /.well-known/security.txt.

2. In scope

  • gtaup.com and subdomains we operate;
  • Authentication, authorization, and access-control flaws on the Service;
  • Injection, SSRF, insecure direct object references, and similar application vulnerabilities;
  • Issues that could expose other users' files or account data without authorization.

3. Out of scope

  • Denial-of-service / volumetric flooding;
  • Social engineering of staff or users;
  • Spam, phishing content hosted by users (use abuse reporting);
  • Reports from automated scanners without a demonstrated impact;
  • Physical attacks or attacks on third-party providers.

There is no bug bounty program at this time. We still welcome coordinated disclosure.

4. Safe harbor

If you make a good-faith effort to follow this policy — avoid privacy violations, data destruction, and service disruption, and give us a reasonable time to remediate before public disclosure — we will not pursue legal action against you for that research. We ask that you do not access or modify data that is not yours beyond what is needed to prove the vulnerability.

5. Response targets

  • Acknowledge receipt: within 3 business days;
  • Initial triage: within 14 days;
  • Remediation target: within 90 days where practicable (we will communicate if more time is needed).