Vulnerability disclosure

Report a security issue.

We take security reports seriously and we welcome them. This page explains how to report safely, what is in scope, and how we will respond.

Our commitment

  • We will acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and fix the issue.
  • We will not take legal action against researchers who follow this policy and act in good faith.
  • With your permission, we will credit you once the issue is fixed.

Scope

In scope: arventiqlabs.com and its API, FortifyHub and other Arventiq Labs products and portals, and our mobile or desktop software.

Out of scope: social engineering of our staff or customers, physical attacks, denial-of-service testing, automated scanning that degrades service, and issues in third-party services we do not control (report those to the vendor).

What we ask

  • Test only against accounts you own or have permission to use; never access, modify or delete other people's data.
  • Stop and report as soon as you confirm a vulnerability — do not go further to "prove" impact.
  • Give us reasonable time to fix the issue before any public disclosure (we aim for 90 days).
  • Do not demand payment as a condition of disclosure. We do not currently run a paid bug bounty.

How to report

Use the form on this page, or email [email protected] with the subject "Security report". Machine-readable details are in our security.txt (RFC 9116). If your report contains sensitive details, tell us and we will arrange an encrypted channel.

What to include

  • The affected URL, product or component.
  • Steps to reproduce, with screenshots or a proof-of-concept if you have one.
  • Your assessment of impact.
  • How we can reach you (optional — anonymous reports are accepted).

Policy version 1.0 · Effective 1 October 2026 · Owner: Arventiq Labs LLP security team.

Submit a report

Describe the issue clearly. Do not include passwords or other people's personal data.