Responsible Disclosure

How to report a security vulnerability in arrtech.ai or an ARRTECH product, and what we commit to in return.

Last updated September 10, 2026

ARRTECH builds security software, so we expect people to test ours. If you find a vulnerability in arrtech.ai or in an ARRTECH product, we want to hear about it, and this page explains how. Reports go to one address, security@arrtech.ai, which is also our product security incident response (PSIRT) contact.

Scope

This policy covers arrtech.ai and its subdomains, services that ARRTECH operates itself, and ARRTECH products, including the Cyberdroid platform, wherever they are deployed. If you find an issue in a customer’s deployment of an ARRTECH product, report it to us and we will coordinate with the customer.

Out of scope

  • Third-party services we use but do not operate, such as the consultation booking widget. Those belong to their providers’ own programs.
  • Denial of service, resource exhaustion, and any volumetric testing.
  • Social engineering of ARRTECH staff, customers, or partners.
  • Physical attacks on facilities or hardware.
  • Findings that require an already compromised device or account to exploit.
  • Output from automated scanners with no demonstrated impact.

How to report

Email security@arrtech.ai. Include the product or URL affected, the steps to reproduce, and the impact you believe the issue has. Proof-of-concept code and screenshots help. A working exploit is not required.

We do not publish a PGP key yet. If your report contains sensitive material, send a first message with no details and we will set up an encrypted channel before you share them.

What we do with a report

We acknowledge every report within three business days. We confirm whether we can reproduce the issue, tell you what we plan to do about it, and keep you informed until it is fixed. We aim to resolve confirmed vulnerabilities within 90 days of the report, and sooner for anything actively exploitable. If a fix needs coordination with customers or a third party, we will tell you and agree on a timeline with you.

Guidelines for researchers

To keep your research inside this policy:

  • Test only systems in scope, and only as far as needed to demonstrate the issue.
  • Do not access, modify, delete, or exfiltrate data that is not your own.
  • If you reach personal data, customer data, or credentials, stop, record only what is needed to report the finding, and tell us.
  • Do not degrade service for other users.
  • Do not use a finding to pivot into other systems, to keep access, or to show impact beyond a proof of concept.
  • Do not share the vulnerability with anyone else before it is fixed, except as described under Public disclosure below.

Safe harbor

If you follow this policy in good faith, we treat your research as authorized. This page is the written authorization for security testing referred to in our Terms of Use. We will not pursue or recommend legal action against you for research conducted under it, and we will not pursue claims against you for circumventing technical controls to the extent that was necessary to conduct the research.

This authorization covers ARRTECH’s own claims. It does not bind third parties, and it does not cover systems outside scope. If a third party threatens legal action over research conducted under this policy, tell us and we will make it known that the research was authorized.

Public disclosure

We prefer coordinated disclosure. We ask that you not publish details until we have fixed the issue or 90 days have passed since your report, whichever comes first, unless we agree on something else with you. If we need more than 90 days, we will explain why and propose a date. Once the issue is fixed you are free to publish, and we will review a draft for accuracy if you want us to.

Recognition

We do not run a bug bounty program and do not pay for reports. If you want it, we will credit you by name or handle on this page once the issue is resolved.

security.txt

Our security contact details are also published in machine-readable form at security.txt.

Contact

security@arrtech.ai. ARRTECH Corporation, 14205 SE 36th St, Suite 100, Bellevue, WA 98006.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.