generated: '2026-07-18' method: searched probe: true source: https://arch.co/vulnerabilitydisclosure.html policy: - https://arch.co/vulnerabilitydisclosure.html contact: - security@arch.co bug_bounty: false summary: >- Arch publishes a Vulnerability Disclosure Policy. Report suspected vulnerabilities by emailing security@arch.co; Arch acknowledges within five business days and aims to resolve critical issues within five business days of disclosure. Researchers must make a good-faith effort to avoid violating privacy, destroying data, or degrading the service, and must refrain from DDoS, spam, social engineering/phishing of employees, and attacks on physical property/data centers. Researchers are asked to notify Arch and obtain permission before conducting security research. No public bug bounty program (HackerOne/Bugcrowd/Intigriti) is advertised. evidence: - {source: https://arch.co/vulnerabilitydisclosure.html, kind: disclosure-page, keywords: [security@arch.co, responsible disclosure, safe harbor]}