Skip to main content
Gerai information centre

Security at Gerai

A factual description of Gerai’s public security boundaries, payment architecture, and reporting route.

Effective
Last updated
Authoritative language
English

Scope of this page

This page explains the security boundaries Gerai can state publicly today. It is not a complete description of every technical or organisational control, and it does not expand any commitments made in a customer’s written agreement.

Payment boundary

Gerai connects storefront payment flows to licensed payment gateways. Those gateways handle buyer payment credentials and payment processing within their own regulated and contractual environments.

  • Payment credentials are handled by the licensed payment gateway, not by Gerai.
  • Settlement is made directly from the payment gateway to the merchant.
  • Gerai does not receive, hold, or control buyer funds.

A merchant’s relationship with its selected payment gateway, including gateway onboarding, account security, settlement, disputes, and gateway terms, remains separate from the merchant’s use of Gerai.

Shared responsibility

Security depends on clear ownership across Gerai, merchants, and the licensed services a merchant chooses to connect.

Publicly stated security boundaries
AreaPrimary responsibilityBoundary
Gerai serviceGeraiOperating the Gerai website and merchant platform within the agreed service scope.
Merchant account and contentMerchantControlling authorised users, account access, product information, customer handling, and lawful use of connected services.
Payment credentials and processingLicensed payment gatewayThe gateway handles payment credentials and processes payment under its own terms.
SettlementLicensed payment gateway and merchantSettlement goes directly to the merchant; Gerai does not hold buyer funds.

Reporting a security concern

Send suspected vulnerabilities, unauthorised access concerns, or other security reports to hello@gerai.shop. Include enough detail for Gerai to understand and reproduce the issue, while avoiding unnecessary personal data or sensitive information.

A useful report normally includes:

  • the affected page, account, or feature;
  • a clear description of the observed behaviour and expected behaviour;
  • reproduction steps, dates, and relevant screenshots or logs; and
  • a safe way to contact the reporter for follow-up.

Do not disrupt services, access data that is not yours, degrade availability, or publicly disclose an unresolved issue in a way that could increase harm.

How reports are handled

Gerai reviews incoming reports, assesses the affected service and information, and takes proportionate steps to contain, investigate, recover, and communicate. The appropriate actions depend on the facts and legal or contractual obligations that apply.

The Incident Response page explains this process in more detail. Possible service interruptions can be reported through the route on the Service Status page.

Assurance and related information

Public pages are intended to make Gerai’s current boundaries understandable; they are not substitutes for due diligence or negotiated terms. Procurement teams can review the following related information:

  • Privacy Policy for Gerai’s handling of personal data;
  • Subprocessors for the disclosure and contracting process for relevant service providers;
  • Data Residency for location-specific requirements; and
  • Contact Gerai to discuss written security or procurement requirements before onboarding.
Security at Gerai | Gerai