Incident Response
How Gerai receives, assesses, contains, recovers from, and communicates about reported security and service incidents.
This public overview does not create fixed response, recovery, notification, or update times. Customer-specific commitments apply only when recorded in a written agreement.
Scope and principles
An incident may involve suspected unauthorised access, loss of confidentiality or integrity, service disruption, misuse, or another event that requires coordinated assessment. Not every alert, error, or support request is a confirmed security incident or personal data breach.
Gerai’s response is organised around five practical stages:
- intake and preservation of useful information;
- assessment of facts, scope, impact, and obligations;
- containment of ongoing harm where possible;
- recovery, validation, and follow-up review; and
- communication appropriate to affected parties and applicable requirements.
1. Intake
Gerai receives reports through its published contact route and gathers enough information to begin triage. Intake can include the reporter’s description, affected account or storefront, relevant times, reproduction steps, error messages, and safely shared evidence.
Reporters should avoid sending passwords, full payment credentials, unnecessary personal data, or information belonging to others. Licensed payment gateways handle payment credentials within their own environments; Gerai does not hold buyer funds.
2. Assessment
Gerai assesses available facts to determine:
- whether the report concerns Gerai, a merchant-controlled configuration, or another provider;
- which services, accounts, data, and people may be affected;
- whether activity is ongoing and what evidence should be preserved;
- the potential operational, security, privacy, and legal impact; and
- who should participate in the next steps.
Early assessments can change as evidence develops. Gerai may need information from the reporter, an affected merchant, or a connected service before reaching a conclusion.
3. Containment
Where Gerai identifies a credible ongoing risk within its control, containment focuses on reducing further harm while preserving the ability to investigate. Depending on the facts, this may involve restricting an affected path, changing access, isolating a component, pausing a workflow, or coordinating with a relevant service provider or merchant.
A containment action can temporarily reduce functionality and is not necessarily a final fix. Gerai weighs urgency, evidence, operational impact, and the risk of making the situation harder to understand or recover from.
4. Recovery and review
Recovery aims to restore appropriate service safely, validate that the immediate issue has been addressed, and monitor for recurrence where relevant. Gerai may also document the event, contributing conditions, decisions, and corrective actions.
Follow-up can include technical changes, configuration updates, process changes, additional guidance, or work with a connected provider. The appropriate depth of review depends on the incident’s impact and the evidence available.
5. Communication
Gerai considers who needs information, what can be stated reliably, and whether law or a written agreement requires a particular notice. Communication may be directed to affected merchants, individuals, service providers, advisers, insurers, or authorities as applicable.
Where appropriate, a communication can explain:
- what is known and what remains under investigation;
- the affected service, data, or period;
- containment and recovery steps taken;
- practical actions the recipient should consider; and
- how further material information will be provided.
Gerai does not use the Service Status page as an automated or authoritative live incident feed. Direct communication and any legally required notices are handled according to the incident’s facts and the applicable relationship.
How to report
Send suspected security incidents, vulnerabilities, or material service concerns to hello@gerai.shop. Use a clear subject such as “Security report” or “Service incident” and provide the safest useful detail available.
See Security at Gerai for the reporting boundary and the Privacy Policy for information about personal data supplied in correspondence.
Legal review notice
This published document explains Gerai’s current approach and intended practices. It does not constitute legal advice to the reader. Gerai recommends obtaining advice from a qualified lawyer about the laws and contractual requirements that apply to your circumstances.