Responsible Vulnerability Disclosure Policy
Guidelines for security researchers and ethical hackers to responsibly discover and report vulnerabilities in Arzenlabs applications and edge endpoints.
1. Commitment to Security Research & Safe Harbor
At Arzenlabs ("Arzenlabs"), we welcome contributions from the independent security research community to help keep our applications, infrastructure, and technical platforms secure.
If you conduct security research in accordance with the guidelines set forth in this Policy, we consider your research to be authorized, and we commit to not initiating legal action against you ("Safe Harbor").
2. Scope of Eligible Research
The following targets are within the scope of our Responsible Disclosure Program:
- Primary Web Application:
https://arzenlabs.com&https://www.arzenlabs.com - CMS Backend & API Routes:
https://cms.arzenlabs.com&https://arzenlabs-backend.vercel.app - Public Software Repositories & Libraries published under the official ArzenLabs GitHub organization.
3. Researcher Rules of Engagement & Restrictions
To qualify for Safe Harbor, researchers must strictly adhere to the following rules:
- No Customer Data Access: Do not access, modify, or download data belonging to Arzenlabs customers or third parties. If you encounter personal data, stop testing immediately and report the issue.
- No Destruction or Alteration: Do not execute commands that destroy, corrupt, or alter operational system data or database records.
- No Service Disruption: Do not perform Denial of Service (DoS/DDoS) attacks, spam, or high-frequency automated stress tests against production systems.
- No Social Engineering: Do not perform phishing, spear-phishing, or physical intrusion attempts against Arzenlabs employees, offices, or data center locations.
- Confidentiality: Maintain strict confidentiality and do not disclose details of an unpatched vulnerability to the public or third parties without written authorization from Arzenlabs.
4. Vulnerability Reporting & Response SLA
Please submit security vulnerability reports to our dedicated security contact:
Response Commitments:
- Acknowledgment: Within 48 hours of report receipt.
- Triage & Assessment: Within 5 business days.
- Remediation Updates: Periodic status updates until patching is complete.
5. Bug Bounty Disclaimer
Note on Bounties: Arzenlabs currently operates a non-monetary recognition program. We provide public attribution (with researcher consent) in our Security Wall of Thanks and issue formal letters of appreciation for verified, high-impact security discoveries.
Arzenlabs seeks to comply with applicable data protection and privacy laws including the Digital Personal Data Protection Act (DPDP) 2023, Information Technology Act 2000, and applicable international privacy principles.