We take security reports seriously and we welcome them. This page explains how to report safely, what is in scope, and how we will respond.
In scope: arventiqlabs.com and its API, FortifyHub and other Arventiq Labs products and portals, and our mobile or desktop software.
Out of scope: social engineering of our staff or customers, physical attacks, denial-of-service testing, automated scanning that degrades service, and issues in third-party services we do not control (report those to the vendor).
Use the form on this page, or email [email protected] with the subject "Security report". Machine-readable details are in our security.txt (RFC 9116). If your report contains sensitive details, tell us and we will arrange an encrypted channel.
Policy version 1.0 · Effective 1 October 2026 · Owner: Arventiq Labs LLP security team.
Describe the issue clearly. Do not include passwords or other people's personal data.
Thank you. We will review it and respond within 3 business days.