How to report
Email support@arkoncybersecurity.com with the affected URL or version, impact, safe reproducible steps using non-sensitive test data, timestamps and time zone, and your preferred contact. Never send passwords, PATs, cookies, private keys, live customer content, payment-card data, or Stripe secrets.
Priority issues
Prioritize cross-tenant access, authentication or session bypass, credential exposure, connector scope escalation, remote code execution, unsafe installer or update behavior, billing-entitlement bypass, and sensitive-data disclosure.
Safe-harbor boundaries
We will not pursue legal action for good-faith research that follows this policy, uses only accounts and tenants the researcher owns, avoids privacy violations and service disruption, stops after confirming the issue, promptly reports it, and allows reasonable remediation time before disclosure. This does not authorize access to another customer, social engineering, credential attacks, persistence, malware, extortion, denial of service, destructive testing, or violation of third-party systems or law.
Response targets
We aim to acknowledge a report within three business days and provide a status update at least every ten business days while actively investigating. Severity is based on exploitability, affected data or tenants, required privileges, and operational impact. We will coordinate a reasonable disclosure date after remediation or mitigation.
No automatic bounty
Arkon Vault does not currently operate a paid bug-bounty program. No payment or reward is promised unless agreed in writing before the work.
