Back to Home
Bug Bounty Program
We value the work of the security community. Report vulnerabilities in good faith and help us keep Arcta and our customers safe.
How to report
Until our public program is live on a third-party platform, please report issues directly to our security team. Provide detailed reproduction steps, impacted URLs, and any proof-of-concept.
Program details
In scope
- Production app: app.arcta.ai
- Primary API endpoints under app.arcta.ai/api
- Common web vulnerabilities (OWASP Top 10)
Out of scope
- Denial of Service (DoS), rate limiting, or volumetric attacks
- Automated scanning without prior approval
- Social engineering, physical attacks, or third-party services
Coordinated disclosure & safe harbor
We will not pursue legal action against researchers who report vulnerabilities in good faith, avoid privacy violations and service disruptions, and give us a reasonable time to remediate before public disclosure.