Announcing Arbitex's Coordinated Vulnerability Disclosure Program
Security researchers need two things from a vendor before they’ll bother sending a report: a clear way to reach someone technical, and confidence that the response won’t be a legal threat. Today we’re formalizing both.
Arbitex now publishes a coordinated vulnerability disclosure program — a written policy, a monitored inbox, a PGP key for anything sensitive, and a documented commitment to work with researchers who engage in good faith.
What’s live
Four resources, all discoverable from any page via the footer:
- /.well-known/security.txt — the RFC 9116 machine-readable contact file. PGP-clearsigned so the listed fingerprint can be verified before you send anything.
- /.well-known/[email protected] — the public PGP key for
[email protected]. Fingerprint:5090 D51D 205C 9D7C 8988 63DA D56D 9DAA 8C13 C78B. - /security/policy — the full policy: assets in scope, rules of engagement, safe-harbor, how to report, response SLAs, and what we generally will not accept.
- /security/acknowledgments — where researchers who ask for credit get it. Empty today; that changes the moment the first qualifying report lands.
The primary reporting channel is [email protected]. Use it.
What safe harbor actually means here
The policy is adapted from disclose.io Core Terms and says, in substance: if you stay within scope, avoid disrupting production or other customers, do not exfiltrate or retain data beyond what’s needed to demonstrate the issue, and give us a reasonable window to fix things before you publish — we will not pursue or support legal action against you, and we will coordinate public disclosure with you.
That is the deal. It is a real deal, not a marketing paragraph. The policy lists the specific activities covered and the specific activities that are not covered. Read it before you test.
What researchers can expect
Timelines are measured in business days from receipt at [email protected]:
- Acknowledgment of your report within 2 business days.
- Initial triage and severity classification within 5 business days.
- Remediation timelines scoped to severity, communicated back to you, with progress updates.
- Public disclosure coordinated with you — we aim for 90 days for most issues, shorter for low-risk items, longer only when there’s an active remediation that would be harmed by disclosure.
If you want public credit, we will list you. If you want to stay anonymous, we will honor that.
What we generally won’t accept
Reports that don’t move into scope on their own: missing security headers on pages that don’t handle sensitive content, TLS configuration reports without demonstrated exploit, automated scanner output without manual verification, social-engineering of staff, physical attacks on infrastructure, SPF/DKIM/DMARC issues on domains that are correctly configured, CVE-number reports against third-party libraries without a demonstrated exploit path in our environment.
A well-reasoned impact argument will move many of these into scope. We read every report.
Why now
Our own security bar moved first. Over the last quarter we ran a three-model adversarial codebase audit — Claude Opus, GLM-5, and Kimi K2.5 reviewing each other’s reviews — closed every P0 finding, and tightened the fail-closed pathways across every DLP tier. Publishing a disclosure program without that work first would have been a way to generate a backlog, not a way to get better.
With the P0 remediation closed and P1 remediation already in flight, opening the door to external researchers is the natural next step. Independent eyes find the things internal eyes stop seeing.
Credit and compensation
Researchers who follow the policy and submit qualifying reports are eligible for public acknowledgment at /security/acknowledgments. Monetary awards are issued at our discretion based on severity, impact, and report quality — we don’t publish a bounty table because we don’t want researchers to optimize around it.
If you find something
Email [email protected]. Encrypt to the published PGP key if the finding is sensitive. Tell us what you did, what you saw, and what impact you think it has. If English isn’t your first language, send it anyway — we can work through translation.
We’re grateful to anyone who takes the time to help us find what we missed.
Full policy at arbitex.ai/security/policy. PGP key fingerprint verification is out-of-band; do not trust a key you only retrieved from our site.