Found something? Tell us first.
Arclave welcomes reports from security researchers. If you believe you have found a vulnerability, please tell us before you tell anyone else — and we will work with you to fix it. Good-faith research under this policy is authorised, and we say so in writing below.
Contact: security@arclave.com · We acknowledge every report within 3 business days. Preferred language: English. We do not currently operate a paid bug bounty — we would rather tell you that now than after you have done the work.
What to include
The more of this you can give us, the faster we can confirm and fix it.
- The product, page or endpoint affected, and its URL.
- What you did, step by step, so we can reproduce it.
- What you observed, and what you expected instead.
- Why you believe it matters — the impact, in your own words.
- Any proof-of-concept code, screenshots, or request and response captures.
- How you would like to be credited, if at all.
What we commit to
- We acknowledge within 3 business days.
- We give you an initial assessment within 10 business days — whether we can reproduce it, and our provisional severity.
- We keep you informed while we work, and we tell you when it is fixed.
- We credit you publicly if you want the credit, and we stay silent about you if you do not.
- We will not pursue or support legal action against you for research conducted in good faith under this policy.
What we ask of you
- Give us time to fix it. We ask for 90 days from your first report before public disclosure, and we will usually be faster. If a fix will take longer, we will tell you why and agree a date with you.
- Do not access, modify, or delete data that is not yours. If you encounter customer data, stop, and tell us what you saw so we can assess exposure.
- Do not degrade the service. No denial-of-service testing, no automated scanning that generates disruptive load, no spam or social engineering of our staff, customers or vendors.
- Do not use physical attacks against our offices or people.
- Work only against systems in scope, below.
Scope
In scope
arclave.comand its subdomains.app.arclave.com— the Decision Console.- The Arclave application programming interfaces (APIs).
Out of scope
- Third-party services we use but do not operate — including Microsoft Azure, Microsoft Entra ID, GitHub, and our compliance-automation vendor. Report those to the vendor concerned; we will help route the report if you ask.
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing security headers, cookie flags, or Transport Layer Security (TLS) configuration weaknesses with no demonstrated exploit.
- Denial of service, volumetric testing, and rate-limiting findings.
- Social engineering, phishing, or physical access attempts.
- Reports of software versions without a working exploit against our deployment.
- Vulnerabilities requiring an already-compromised device or a privileged local account.
Safe harbour
If you follow this policy in good faith, Arclave will treat your research as authorised, will not initiate legal action against you, and will not report you to law enforcement. If a third party brings action against you for research conducted within this policy, we will make it known that your activity was authorised.
This safe harbour applies only to Arclave's own systems. It cannot and does not authorise testing against any third party.
Machine-readable
Our contact details are also published as a security.txt file under RFC 9116, at https://www.arclave.com/.well-known/security.txt.
Thank you.
Reports from researchers make the product safer for everyone who uses it. We are grateful for them, and we try to be the kind of company that is easy to report to.
Last updated 11 August 2026.