generated: '2026-07-19' method: searched probe: true source: https://new.gcash.com/.well-known/security.txt policy: - https://gcash.com/vulnerability-disclosure-program/policy contact: - https://gcash.com/vulnerability-disclosure-program/report - mailto:vulnerability-disclosure@gcash.com security_txt: url: https://gcash.com/.well-known/security.txt preferred_languages: en expires: '2026-07-20T01:00:00.000Z' hiring: offsec@gcash.com program: type: voluntary non-monetary vulnerability disclosure (no bug bounty / no monetary reward) safe_harbor: >- Good-faith researchers adhering to program rules are not pursued legally; safe harbor voided by data exfiltration, service disruption, public disclosure, or use of unauthorized reporting channels. scope_assets: - GCash Android and iOS apps - '*.gcash.com' - '*.mynt.xyz' - FUSE Lending and MYNT websites in_scope_examples: [RCE, SQLi, XSS, account takeover, privilege escalation, broken access control, SSRF, XXE, IDOR, auth/authz bypass, business logic] out_of_scope_examples: [missing security headers, self-XSS, CSRF without impact, user enumeration, scanner-only reports, social engineering, known third-party lib issues] evidence: - source: https://gcash.com/.well-known/security.txt kind: security.txt (live probe) - source: https://gcash.com/vulnerability-disclosure-program/policy kind: disclosure policy page