Security at Gerai
A factual description of Gerai’s public security boundaries, payment architecture, and reporting route.
Scope of this page
This page explains the security boundaries Gerai can state publicly today. It is not a complete description of every technical or organisational control, and it does not expand any commitments made in a customer’s written agreement.
Payment boundary
Gerai connects storefront payment flows to licensed payment gateways. Those gateways handle buyer payment credentials and payment processing within their own regulated and contractual environments.
- Payment credentials are handled by the licensed payment gateway, not by Gerai.
- Settlement is made directly from the payment gateway to the merchant.
- Gerai does not receive, hold, or control buyer funds.
A merchant’s relationship with its selected payment gateway, including gateway onboarding, account security, settlement, disputes, and gateway terms, remains separate from the merchant’s use of Gerai.
Reporting a security concern
Send suspected vulnerabilities, unauthorised access concerns, or other security reports to hello@gerai.shop. Include enough detail for Gerai to understand and reproduce the issue, while avoiding unnecessary personal data or sensitive information.
A useful report normally includes:
- the affected page, account, or feature;
- a clear description of the observed behaviour and expected behaviour;
- reproduction steps, dates, and relevant screenshots or logs; and
- a safe way to contact the reporter for follow-up.
Do not disrupt services, access data that is not yours, degrade availability, or publicly disclose an unresolved issue in a way that could increase harm.
How reports are handled
Gerai reviews incoming reports, assesses the affected service and information, and takes proportionate steps to contain, investigate, recover, and communicate. The appropriate actions depend on the facts and legal or contractual obligations that apply.
The Incident Response page explains this process in more detail. Possible service interruptions can be reported through the route on the Service Status page.
Assurance and related information
Public pages are intended to make Gerai’s current boundaries understandable; they are not substitutes for due diligence or negotiated terms. Procurement teams can review the following related information:
- Privacy Policy for Gerai’s handling of personal data;
- Subprocessors for the disclosure and contracting process for relevant service providers;
- Data Residency for location-specific requirements; and
- Contact Gerai to discuss written security or procurement requirements before onboarding.