arqu welcomes reports of security vulnerabilities in our systems. This page explains how to report one, what is in scope, and our commitment to researchers who report in good faith.
How to report
Email security@arqu.co with the vulnerability, the affected asset (URL or endpoint), steps to reproduce, and the impact as you see it. Report promptly, and give us a reasonable time to fix the issue before disclosing it publicly.
What to expect
- We monitor security@arqu.co and review the reports we receive.
- We do not run a paid bug-bounty program and do not pay for unsolicited reports.
Scope
In scope: any service we run on our own domains — arqu.co, arqu.com, and their subdomains.
Out of scope:
- Systems we do not operate — third-party services and SaaS we use (report those to the vendor).
- Attacks on our people or availability — social engineering, phishing, physical access, and denial of service.
- Automated scanner output with no demonstrated, reproducible impact.
Safe harbour
If you make a good-faith effort to comply with this policy, we will:
- Treat your research as authorised under the Computer Fraud and Abuse Act and similar laws.
- Not pursue or support legal action against you.
- Work with you to resolve the issue.
To stay in good faith:
- Stay within the scope above.
- Do not access, change, or take data that is not yours.
- Avoid privacy violations, service disruption, and data destruction.
- Use only your own test accounts.
- Do not disclose a vulnerability publicly until we have had a reasonable chance to fix it.
This safe harbour applies only while your activity stays consistent with this policy. If in doubt, ask at security@arqu.co first.