How to report a security vulnerability in arrtech.ai or an ARRTECH product, and what we commit to in return.
Last updated September 10, 2026
ARRTECH builds security software, so we expect people to test ours. If you find a vulnerability in arrtech.ai or in an ARRTECH product, we want to hear about it, and this page explains how. Reports go to one address, security@arrtech.ai, which is also our product security incident response (PSIRT) contact.
This policy covers arrtech.ai and its subdomains, services that ARRTECH operates itself, and ARRTECH products, including the Cyberdroid platform, wherever they are deployed. If you find an issue in a customer’s deployment of an ARRTECH product, report it to us and we will coordinate with the customer.
Email security@arrtech.ai. Include the product or URL affected, the steps to reproduce, and the impact you believe the issue has. Proof-of-concept code and screenshots help. A working exploit is not required.
We do not publish a PGP key yet. If your report contains sensitive material, send a first message with no details and we will set up an encrypted channel before you share them.
We acknowledge every report within three business days. We confirm whether we can reproduce the issue, tell you what we plan to do about it, and keep you informed until it is fixed. We aim to resolve confirmed vulnerabilities within 90 days of the report, and sooner for anything actively exploitable. If a fix needs coordination with customers or a third party, we will tell you and agree on a timeline with you.
To keep your research inside this policy:
If you follow this policy in good faith, we treat your research as authorized. This page is the written authorization for security testing referred to in our Terms of Use. We will not pursue or recommend legal action against you for research conducted under it, and we will not pursue claims against you for circumventing technical controls to the extent that was necessary to conduct the research.
This authorization covers ARRTECH’s own claims. It does not bind third parties, and it does not cover systems outside scope. If a third party threatens legal action over research conducted under this policy, tell us and we will make it known that the research was authorized.
We prefer coordinated disclosure. We ask that you not publish details until we have fixed the issue or 90 days have passed since your report, whichever comes first, unless we agree on something else with you. If we need more than 90 days, we will explain why and propose a date. Once the issue is fixed you are free to publish, and we will review a draft for accuracy if you want us to.
We do not run a bug bounty program and do not pay for reports. If you want it, we will credit you by name or handle on this page once the issue is resolved.
Our security contact details are also published in machine-readable form at security.txt.
security@arrtech.ai. ARRTECH Corporation, 14205 SE 36th St, Suite 100, Bellevue, WA 98006.