Vulnerability Disclosure Policy

Last updated: September 5, 2026

If you have found a security problem in ArcNautical, we want to hear about it, and we will not come after you for telling us.

How to report

Email [email protected] with the subject line beginning SECURITY. Machine-readable contact details are at /.well-known/security.txt.

Useful reports include the affected URL or endpoint, the steps to reproduce, what an attacker could achieve, and any request or response captures. A proof of concept is welcome; a working exploit against another customer's data is not, and is not necessary to make your point.

What to expect from us

We do not currently run a paid bug bounty. We are a one-person company and would rather be honest about that than imply a reward we cannot fund.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will not pursue or support any legal action against you in connection with it, and we will help make clear that your actions were authorised if a third party raises them.

If legal action is brought by someone else against you for activity that complied with this policy, we will say so publicly.

Scope

In scope: arcnautical.com and its subdomains, the public API at arcnautical.com/api, and the ArcNautical web application.

Out of scope, and please do not report these:

Rules

Related

Trust & Security · Data Processing Addendum · Privacy Policy · Terms of Service