Responsible Disclosure

Arctickey welcomes responsible disclosure of security issues affecting the service, dashboard, APIs, infrastructure, or customer data isolation.

Security Contact#

Email security reports to security@arctickey.com.

If that address is unavailable, use hello@arctickey.com and include Security report in the subject.

What To Include#

  • A clear description of the issue.
  • The affected URL, endpoint, instance behavior, or component.
  • Reproduction steps or a proof of concept.
  • Impact assessment, including whether customer data may be affected.
  • Your preferred contact details for follow-up.

Rules of Engagement#

Do:

  • Use your own account and test data.
  • Stop testing once you have enough evidence to report the issue.
  • Give Arctickey reasonable time to investigate and remediate before public disclosure.

Do not:

  • Access, modify, delete, or exfiltrate another customer's data.
  • Run denial-of-service tests or resource exhaustion attacks.
  • Use social engineering, phishing, spam, or physical attacks.
  • Persist access or install malware.

Response Expectations#

Arctickey aims to acknowledge security reports within 2 business days and provide follow-up as remediation progresses.

Scope#

In scope:

  • Arctickey dashboard and APIs.
  • Customer instance provisioning and isolation.
  • Authentication, authorization, billing flows, and account deletion.
  • EU data residency controls and operational metadata handling.

Out of scope:

  • Issues requiring compromised customer credentials.
  • Vulnerabilities in third-party services outside Arctickey control unless they directly affect Arctickey configuration.
  • Automated scanner reports without a demonstrated impact.