Skip to main content

Reporting a security vulnerability (Responsible Disclosure)

At ARQ, we take the security of our products and our customers' data seriously, and we're grateful to the security research community for helping us stay safe. If you believe you've found a security vulnerability, we'd love to hear from you.

How to report

We handle all vulnerability reports through our Responsible Disclosure Program, which we run in partnership with Bugcrowd. To submit a report, please visit our Responsible Disclosure Policy page:

You'll find the Bugcrowd submission form linked on that page — please submit your findings directly there.

Please note: our customer support team isn't able to receive or investigate security reports directly. Submitting through the program ensures your report reaches our security team quickly and securely, and that it's handled properly.

What happens next

Bugcrowd carries out an initial review of your submission, then routes valid reports to our security team to investigate and address.

To help us review your report quickly, please include:

  • A clear description of the vulnerability and its potential impact

  • Steps to reproduce it (and any affected URLs, endpoints, or screens)

  • Any supporting evidence, such as a proof-of-concept

Responsible disclosure guidelines

To keep everyone protected, we ask that you:

  • Give us reasonable time to investigate and fix an issue before disclosing it publicly

  • Don't access, modify, or delete data that isn't your own

  • Avoid anything that could disrupt our service or affect other customers

  • Act in good faith

Thank you for taking the time to help keep ARQ and our customers secure.

Did this answer your question?