generated: '2026-09-03' method: searched source: https://geekflare.com/security/ program: responsible-disclosure policy_url: https://geekflare.com/security/ reporting_channel: https://geekflare.com/contact/ (vulnerability reports via contact page; no security.txt served) bug_bounty: false security_txt: false statement: "We welcome the contribution of external security researchers. If you believe you have found a vulnerability in Geekflare, please report it to us. Please send vulnerability reports through contact page." practices_published: - Infrastructure on AWS and Cloudflare (provider-inherited ISO 27001 / SOC 2 / PCI DSS — infrastructure vendors' certifications, not Geekflare's own) - TLS encryption in transit; API keys stored encrypted at rest - Rate limiting and anomaly detection for DDoS/abuse prevention note: No first-party compliance certifications or trust center found, so no Compliance pointer is emitted; the ISO/SOC/PCI names on the security page belong to AWS/Cloudflare.