Responsible disclosure
How to report a vulnerability and what is in and out of scope.
If you discover a vulnerability in the ARCY SDK or platform:
Email: contact@arcyai.com
Initial response: Within 48 hours.
Triage and resolution: Within 7 days for confirmed issues.
Please do not disclose vulnerabilities publicly until we have had time to assess and patch the issue.
Safe harbor: if you make a good-faith effort to follow this policy, report through the email above, and avoid the excluded targets and methods below, we will not pursue legal action against your research.
In scope: ARCY platform API, ARCY SDK (@arcyai/sdk), frontend applications at arcyai.com and subdomains, authentication and authorization bypasses, cross-organization data access, and any vulnerability caused by how ARCY configures or integrates a third-party provider (for example, a misconfigured storage bucket or a broken check on a Clerk-issued identity).
Out-of-scope targets: the underlying platforms of our providers themselves (Amazon Web Services (AWS), Clerk, Resend, Stripe). Report a vulnerability in one of their platforms directly to them, not to us. A bug in how we use one of these providers is always in scope, see above.
Out-of-scope methods, regardless of target: denial-of-service testing, physical security testing, and social engineering techniques such as phishing our staff or attempting to talk a support agent into an action. This does not exclude reporting a finding about a weak support or account-recovery process, that kind of report is welcome and in scope; we just ask that you describe it rather than test it against real employees or customers without our prior authorization.