Vulnerability Disclosure Policy
Last updated: September 5, 2026
If you have found a security problem in ArcNautical, we want to hear about it, and we will not come after you for telling us.
How to report
Email [email protected] with the subject line beginning SECURITY. Machine-readable contact details are at /.well-known/security.txt.
Useful reports include the affected URL or endpoint, the steps to reproduce, what an attacker could achieve, and any request or response captures. A proof of concept is welcome; a working exploit against another customer's data is not, and is not necessary to make your point.
What to expect from us
- Acknowledgement within 3 business days. If you do not hear back, resend — do not assume you have been ignored.
- An assessment within 10 business days, telling you whether we consider it a vulnerability and, if so, our severity view and rough timeline.
- Notification when it is fixed. We will tell you what we changed.
- Credit in our release notes if you want it, and none if you would rather stay anonymous.
We do not currently run a paid bug bounty. We are a one-person company and would rather be honest about that than imply a reward we cannot fund.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will not pursue or support any legal action against you in connection with it, and we will help make clear that your actions were authorised if a third party raises them.
If legal action is brought by someone else against you for activity that complied with this policy, we will say so publicly.
Scope
In scope: arcnautical.com and its subdomains, the public API at arcnautical.com/api, and the ArcNautical web application.
Out of scope, and please do not report these:
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing security headers, cookie flags, or TLS configuration preferences with no demonstrated exploit.
- Rate limiting on unauthenticated marketing pages.
- Email configuration issues such as SPF, DKIM or DMARC policy strength, absent a working spoofing demonstration.
- Social engineering of the founder or of any customer, and physical attacks.
- Reports that a maritime record we publish is wrong. That is a data quality issue, not a vulnerability — write to [email protected] without the SECURITY prefix and we will look into the source.
Rules
- Use only your own accounts and your own test data. If you access another party's data accidentally, stop, tell us, and delete what you retrieved.
- Do not run denial of service tests, and do not use automated scanning at a volume that degrades the service for other users.
- Do not modify or destroy data, and do not persist access.
- Give us a reasonable opportunity to fix the issue before disclosing it publicly. We will agree a date with you; if we go quiet, 90 days from your report is a reasonable default and we will not object to disclosure after it.
Related
Trust & Security · Data Processing Addendum · Privacy Policy · Terms of Service