Vulnerability Disclosure Policy
1. Introduction
We at Third Frontier Ventures Ltd. trading as Arcla (“we”, “us”, “our”) take the security of our systems and the privacy of our users seriously. We welcome responsible disclosure from security researchers and members of the public who discover vulnerabilities in our products and services.
This policy sets out how to report a vulnerability, what you can expect from us, and what we ask of you in return.
2. Scope
In scope
The following systems and services are in scope for this programme:
arcla.com— our marketing websitedash.arcla.com— the Arcla web application
Out of scope
The following are explicitly out of scope:
- Social engineering attacks against Arcla staff or contractors
- Physical attacks against our offices, data centres, or equipment
- Denial-of-service (DoS or DDoS) attacks
- Vulnerabilities in third-party services or libraries that we use but do not control
- Issues requiring physical access to a user’s device
- Spam or email deliverability issues
If you are unsure whether a particular system or finding is in scope, please contact us before proceeding.
3. How to report
Please send your report by email to security@arcla.com. To help us triage and resolve the issue as quickly as possible, include:
- A clear description of the vulnerability and the potential impact
- Step-by-step instructions to reproduce the issue
- An assessment of the severity and affected components
- Proof-of-concept code, screenshots, or other supporting evidence, if available
- Your contact details if you would like us to follow up with you
Please encrypt sensitive reports using our PGP key if you need to share credentials or particularly sensitive details — contact us first and we will provide it.
4. What to expect from us
When you submit a report:
- We will acknowledge receipt within 2 business days
- We will provide a status update within 7 days, including an initial assessment and expected timeline for resolution
- We aim to resolve critical vulnerabilities within 30 days of confirmation; less severe issues will be addressed on a risk-prioritised basis
- We will notify you when the issue has been resolved and, where appropriate, credit your contribution in our release notes or security acknowledgements (with your permission)
We may ask follow-up questions to better understand the report. We treat all submissions in confidence and will not share your personal details with third parties without your consent.
5. Safe harbour
We support good-faith security research. If you follow this policy, we commit to:
- Not pursuing legal action against you for research conducted in good faith under these guidelines
- Working with you constructively to understand and resolve the issue
- Acknowledging your contribution if you wish
In return, we ask that you:
- Do not access, modify, copy, or delete data belonging to users other than your own test accounts
- Do not degrade or disrupt our services for other users
- Do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate it — we ask for a coordinated disclosure period of at least 90 days from the date we confirm the issue
- Conduct research only on systems explicitly listed as in scope above
- Stop testing and contact us immediately if you encounter any user data during your research
We consider research that violates these terms to be outside the scope of this safe harbour.
6. Out-of-scope issues
The following types of reports are generally out of scope and unlikely to result in a remediation:
- Missing HTTP security headers that do not present a realistic attack path
- Clickjacking on pages without sensitive functionality
- Automated scanner output without a demonstrated exploit
- Rate-limiting or brute-force issues on non-sensitive endpoints
- Self-XSS or issues that require a user to take unlikely or unreasonable actions
- Spam, phishing, or social engineering
- Physical attacks or issues requiring physical access
- Denial-of-service attacks
We reserve the right to assess reports on a case-by-case basis regardless of category.
7. Contact
Security reports and questions about this policy should be sent to:
For general enquiries unrelated to security, please use support@arcla.com.