Security Disclosure

Last updated:

How to report a vulnerability, what's in scope, and our safe-harbour promise to researchers.

On this page
  1. Introduction
  2. Safe harbour
  3. Scope
  4. How to report
  5. What to expect
  6. Recognition

Introduction

We take ArcDemo's security seriously and value the researchers who help us find and fix vulnerabilities. This policy explains how to report an issue safely.

Safe harbour

We won't take legal action against researchers who:

  • act in good faith and within this policy, without harming users or data;
  • test only against accounts and data they own or are authorized to use;
  • avoid privacy violations, data destruction and service degradation;
  • report promptly and don't exploit an issue beyond a proof of concept.

Scope

In scope:

  • the ArcDemo web application and API;
  • the embeddable player and the arcdemo.js embed script;
  • the ArcDemo Chrome extension and macOS recorder.

Out of scope:

  • denial-of-service or volumetric attacks;
  • social engineering or phishing of our staff or customers;
  • automated scanner output without a demonstrated impact;
  • third-party services we use (please report those to the vendor).

How to report

Email security@arcdemo.io and include:

  • a description of the issue and its impact;
  • step-by-step reproduction, with URLs, requests or a proof of concept;
  • the affected part (web app, API, embed script, extension or recorder);
  • your contact details if you'd like updates or credit.

Please don't open a public GitHub issue for security vulnerabilities.

What to expect

  • We'll acknowledge your report within 3 business days.
  • We'll keep you updated while we triage, validate and fix it.
  • We'll agree on disclosure timing with you, and ask you to wait until a fix is out.

Recognition

We don't run a paid bug bounty yet. We're happy to credit researchers who report valid issues, if they'd like to be named.