GSCA Security & Responsible Disclosure Policy
Effective Date: August 9, 2026
Last Updated: August 9, 2026
Global Standard Certified Alliance ("GSCA"), operated by Techevent Limited and its affiliated entities ("GSCA", "we", "us", or "our"), operates a global digital trust infrastructure supporting identity, verification, digital credentials, eAssets, provenance, certification, authentication, and related trust services.
Security and system integrity are fundamental to the GSCA Trust Infrastructure.
This GSCA Security & Responsible Disclosure Policy ("Policy") describes our general approach to security and provides a framework for reporting suspected security vulnerabilities or incidents affecting GSCA Services.
This Policy should be read together with the GSCA Terms of Service, Privacy Policy, Cookie Policy, Acceptable Use & Trust Integrity Policy, Payment, Billing & Refund Policy, and Intellectual Property & Trademark Policy.
1. Our Security Principle
GSCA is designed around the principle that digital trust requires the protection of:
-
Identity;
-
Credentials;
-
Digital assets;
-
Verification records;
-
Provenance information;
-
Authentication mechanisms;
-
Account access;
-
System integrity;
-
Availability of GSCA Services.
GSCA continuously seeks to maintain appropriate technical and organizational safeguards designed to protect the confidentiality, integrity, and availability of information and services within the GSCA ecosystem.
2. Scope of Security
Depending on the applicable GSCA Service, security measures may address:
-
User accounts;
-
ONE ID and identity-related services;
-
Digital certificates;
-
eAssets;
-
eOrigin records;
-
eStamp services;
-
NFC and QR-based verification;
-
APIs and integrations;
-
Cloud infrastructure;
-
Databases and system services;
-
Authentication mechanisms;
-
Access controls;
-
Administrative systems;
-
Network and application security;
-
Security monitoring and logging;
-
Backup and recovery processes.
The specific technical implementation may vary between GSCA Services and may be updated as the GSCA Trust Infrastructure evolves.
3. Identity and Access Security
GSCA may implement appropriate access controls designed to ensure that users and organizations can only access functions and information for which they are authorized.
Depending on the service, security controls may include:
-
Authentication;
-
Multi-factor authentication;
-
Role-based access controls;
-
Account verification;
-
Authorization controls;
-
Credential management;
-
Session controls;
-
Security monitoring;
-
Other appropriate technical safeguards.
Users are responsible for maintaining the confidentiality of their account credentials and for taking reasonable measures to protect their accounts.
4. Data Protection and Encryption
GSCA uses appropriate security measures to protect information processed through its services.
Depending on the applicable system and service, these measures may include:
-
Encryption in transit;
-
Encryption or other protective measures for stored information;
-
Cryptographic verification;
-
Secure authentication;
-
Access controls;
-
Integrity protection;
-
Security monitoring.
GSCA does not publicly disclose sensitive technical details that could materially weaken the security of its systems.
5. Digital Trust and Integrity Protection
Because GSCA operates a Trust Infrastructure, maintaining the integrity of digital records is a core security objective.
GSCA may use technical and organizational controls designed to help protect against:
-
Unauthorized modification;
-
Credential manipulation;
-
Identity fraud;
-
Unauthorized issuance;
-
Counterfeit digital records;
-
Unauthorized asset transfers;
-
Tampering with verification information;
-
Unauthorized access;
-
System abuse.
Where appropriate, GSCA may monitor relevant system activity to identify suspicious behavior or potential security incidents.
6. NFC, QR and Physical Trust Identifiers
Where GSCA Services use NFC tags, QR codes, digital identifiers, or other physical-to-digital trust mechanisms, GSCA may implement controls designed to support:
-
Identifier verification;
-
Authentication;
-
Record integrity;
-
Unauthorized-use detection;
-
Asset association;
-
Verification status.
Users must not attempt to clone, manipulate, redirect, replace, or otherwise misuse GSCA identifiers for fraudulent or unauthorized purposes.
Such activities may constitute a violation of the GSCA Acceptable Use & Trust Integrity Policy.
7. API and Integration Security
Where GSCA provides APIs, SDKs, or other integration services, appropriate security controls may include:
-
Authentication;
-
Authorization;
-
API credentials;
-
Access restrictions;
-
Rate limitations;
-
Monitoring;
-
Logging;
-
Other technical safeguards.
Developers and integration partners are responsible for protecting their API credentials and using GSCA APIs only within the scope of their authorization.
Compromised or suspected compromised credentials should be reported to GSCA as soon as reasonably possible.
8. Security Monitoring
GSCA may monitor system activity and security events to:
-
Detect unauthorized access;
-
Identify suspicious activity;
-
Investigate security incidents;
-
Protect system availability;
-
Protect user accounts;
-
Protect the integrity of GSCA Services;
-
Support incident response;
-
Meet applicable legal or regulatory requirements.
Security records may be retained in accordance with applicable laws, contractual requirements, operational needs, and the GSCA Privacy Policy.
9. Security Incidents
A security incident may include, without limitation:
-
Unauthorized access;
-
Account compromise;
-
Credential compromise;
-
Unauthorized disclosure of protected information;
-
Malware affecting GSCA systems;
-
Significant service disruption;
-
Unauthorized modification of protected records;
-
Suspected compromise of GSCA infrastructure;
-
Other events that may materially affect the security or integrity of GSCA Services.
Where GSCA identifies a security incident, we may take appropriate measures to:
-
Investigate the incident;
-
Contain the affected systems;
-
Protect users and services;
-
Restore affected services;
-
Preserve relevant security information;
-
Assess potential impact;
-
Notify affected parties where required by applicable law or contractual obligations;
-
Implement corrective or preventive measures.
10. Responsible Disclosure
GSCA encourages security researchers, developers, customers, partners, and other responsible individuals to report suspected security vulnerabilities.
Responsible disclosure helps GSCA identify and address security weaknesses before they can be exploited to harm users or compromise the Trust Infrastructure.
If you believe you have identified a security vulnerability affecting a GSCA Service, please report it to us promptly.
11. What to Include in a Security Report
Where possible, a security report should include sufficient information for GSCA to understand and reproduce the issue.
Useful information may include:
-
Description of the vulnerability;
-
Affected GSCA Service;
-
Affected URL, API, application, or function;
-
Steps required to reproduce the issue;
-
Relevant screenshots or technical evidence;
-
Potential security impact;
-
Suggested mitigation, if available;
-
Your contact information.
Please do not include unnecessary personal information or confidential information belonging to other users.
12. Responsible Security Testing
Security researchers and other parties reporting vulnerabilities should:
-
Test only systems and services that are within the intended scope of their authorized activity;
-
Avoid accessing or modifying data belonging to other users;
-
Avoid disrupting GSCA Services;
-
Avoid destructive testing;
-
Avoid denial-of-service testing;
-
Avoid social engineering of GSCA personnel;
-
Avoid physical attacks against GSCA facilities;
-
Avoid installing persistent access mechanisms;
-
Avoid copying or retaining unnecessary personal information;
-
Stop testing when sufficient evidence has been obtained to demonstrate the vulnerability.
Where possible, researchers should use test accounts or their own accounts.
13. Prohibited Security Testing
Unless expressly authorized in writing by GSCA, security testing must not include:
-
Denial-of-service or distributed denial-of-service attacks;
-
Flooding or stress testing intended to disrupt services;
-
Destructive actions;
-
Data deletion or corruption;
-
Unauthorized access to another person's account;
-
Unauthorized access to personal or confidential information;
-
Social engineering of employees, customers, or partners;
-
Physical attacks;
-
Malware deployment;
-
Persistence mechanisms;
-
Credential theft;
-
Exploitation intended to cause material harm.
Unauthorized testing may be treated as a violation of the GSCA Acceptable Use & Trust Integrity Policy and may result in appropriate action.
14. Protection of User Data During Security Research
Security researchers must make reasonable efforts to minimize access to personal, confidential, or proprietary information.
If personal or confidential information is unintentionally accessed during authorized security research, the researcher should:
-
Stop accessing the information;
-
Avoid copying or distributing it;
-
Delete unnecessary copies;
-
Notify GSCA promptly;
-
Provide only the minimum information necessary to demonstrate the vulnerability.
15. Good-Faith Security Research
GSCA encourages good-faith security research conducted responsibly and within the scope of this Policy.
Where a security researcher:
-
Acts in good faith;
-
Avoids unnecessary harm;
-
Does not intentionally access or disclose unrelated confidential information;
-
Reports the vulnerability promptly;
-
Gives GSCA a reasonable opportunity to investigate and address the issue;
GSCA will consider the circumstances when determining an appropriate response.
This Policy does not create a contractual guarantee of immunity from legal action, and it does not authorize activity that is otherwise prohibited by law.
16. Coordinated Disclosure
GSCA may work with security researchers to coordinate the disclosure of significant vulnerabilities.
Depending on the circumstances, GSCA may:
-
Request reasonable time to investigate;
-
Develop and deploy a mitigation;
-
Request that technical details remain confidential temporarily;
-
Coordinate disclosure timing;
-
Acknowledge the contribution of the researcher where appropriate.
GSCA may determine the appropriate disclosure approach based on security risk, user impact, applicable law, and operational considerations.
17. Third-Party Services
GSCA may rely on third-party infrastructure, cloud providers, payment providers, authentication services, communication services, or other technology providers.
Security incidents involving third-party services may be subject to the relevant provider's security procedures and contractual arrangements.
GSCA may work with relevant providers where necessary to investigate and mitigate security incidents affecting GSCA Services.
18. Security Responsibilities of Users
Security is a shared responsibility.
Users should:
-
Protect account credentials;
-
Use strong and unique passwords;
-
Enable additional security controls where available;
-
Keep devices and software reasonably secure;
-
Avoid sharing authentication credentials;
-
Monitor account activity;
-
Report suspected account compromise;
-
Keep contact information reasonably current;
-
Use GSCA Services only through authorized channels.
Organizations should also implement appropriate internal access controls for employees, administrators, agents, and other authorized users.
19. Reporting Account or Credential Compromise
If you believe that your GSCA account, ONE ID, API credentials, authentication credentials, or other security credentials have been compromised, contact GSCA as soon as reasonably possible.
GSCA may take measures including:
-
Credential suspension;
-
Account restriction;
-
Access revocation;
-
Identity verification;
-
Security investigation;
-
Credential replacement;
-
Other protective measures.
20. Security Updates and Improvements
GSCA may periodically update its systems, security controls, software, infrastructure, and procedures.
These changes may include:
-
Security patches;
-
Infrastructure upgrades;
-
Authentication improvements;
-
Monitoring improvements;
-
Access-control changes;
-
Cryptographic improvements;
-
Backup and recovery improvements;
-
Vulnerability remediation.
GSCA may make security-related changes without prior notice where reasonably necessary to protect the Trust Infrastructure or its users.
21. Service Availability and Security
GSCA takes reasonable measures to maintain the availability and resilience of its services.
However, no digital infrastructure can guarantee continuous availability or complete protection against every:
-
Cyberattack;
-
Security vulnerability;
-
Infrastructure failure;
-
Internet disruption;
-
Third-party failure;
-
Natural disaster;
-
Other unforeseen event.
Users should maintain appropriate business continuity and operational procedures where GSCA Services are critical to their activities.
22. No Guarantee of Absolute Security
GSCA implements reasonable technical and organizational security measures appropriate to the nature of its services.
However:
No system, network, application, database, authentication mechanism, or digital trust infrastructure can be guaranteed to be completely secure.
Accordingly, GSCA does not guarantee that its Services will be completely free from vulnerabilities, unauthorized access, security incidents, or other security risks.
23. Relationship with the GSCA Trust Integrity Policy
Security incidents and technical vulnerabilities are distinct from intentional misuse of GSCA Services.
Where conduct involves deliberate abuse, fraud, unauthorized access, credential manipulation, counterfeit credentials, or attempts to undermine GSCA Trust mechanisms, the GSCA Acceptable Use & Trust Integrity Policy may also apply.
GSCA may take action under both policies where appropriate.
24. Security Contact and Vulnerability Reporting
For security concerns, suspected vulnerabilities, compromised credentials, or responsible disclosure reports, please contact:
Global Standard Certified Alliance (GSCA)
Operated by Techevent Limited
Security Contact:
Email: neksun@ecert.app
When reporting a vulnerability, please use the subject:
SECURITY REPORT — [Brief Description]
Please do not publicly disclose sensitive vulnerability details before GSCA has had a reasonable opportunity to investigate and respond.
25. Policy Updates
GSCA may update this Policy from time to time to reflect:
-
Changes in technology;
-
New GSCA Services;
-
Security improvements;
-
New security risks;
-
Changes in applicable laws;
-
Changes in the GSCA Trust Infrastructure;
-
Improvements to incident response procedures.
The latest version will be published on the applicable GSCA website.
Unless otherwise required by law, continued use of GSCA Services after the effective date of an updated Policy constitutes acceptance of the revised Policy.
26. Contact Us
For general questions concerning this Policy, security governance, or GSCA security practices:
Global Standard Certified Alliance (GSCA)
Operated by Techevent Limited
Email: cs@ecert.app
Website: www.ecert.app / www.gsca.cc