LEGAL
Vulnerability Disclosure & Security Policy
How to report security issues in ARCA software and arca.vision infrastructure.
- Effective Date:
- August 28, 2026
- Entity:
- ARCA VISION LABS LLC
- Security Contact:
- observer@arca.vision
- Direct Contact:
- antonio@arca.vision
1. Security Philosophy & Architecture
ARCA VISION LABS LLC engineers privacy-first, zero-trust artificial intelligence and software systems. For our standalone cryptographic software (including ARCA secrets manager at /artifacts/arca), we adhere to strict air-gapped engineering principles: zero networking crates in the cryptographic core, local-only data custody, and auditable open specifications.
We welcome responsible research and disclosure from security professionals and independent researchers to ensure our systems and binaries remain robust.
2. Scope of Policy
This policy applies to:
- ARCA Desktop & CLI Binaries (/artifacts/arca): Cryptographic file format parsing, Argon2id/XChaCha20-Poly1305 implementations, in-memory credential wiping, process memory isolation, and local IPC channels.
- Web Infrastructure: Public-facing assets under the
*.arca.visiondomain.
Out of Scope
- Denial of Service (DoS/DDoS) attacks against web routing infrastructure.
- Social engineering, phishing, or physical attacks against company personnel or facilities.
- Theoretical vulnerabilities in third-party dependencies without a demonstrable, reproducible exploit against our build artifacts.
3. Guidelines for Ethical Research (Safe Harbor)
We consider security research conducted under this policy authorized and will not initiate legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption.
- Perform binary reverse engineering, local fuzzing, and cryptographic analysis strictly on local, non-production test environments.
- Keep discovered vulnerabilities confidential until we have had a reasonable window to investigate, remediate, and publish an advisory (coordinated disclosure).
- Do not exploit a vulnerability beyond the minimum necessary proof of concept required to demonstrate its existence.
4. Reporting a Vulnerability
If you believe you have found a security flaw in our software or web systems, please submit a report immediately to our security intake:
- Primary Security Email: observer@arca.vision
- Escalations: antonio@arca.vision
Please include in your report:
- A detailed description of the vulnerability (e.g., memory corruption, cryptographic edge case, logic bypass).
- Steps to reproduce the issue, including target operating system, binary version/commit hash, sample payloads, or proof-of-concept code.
- The potential attack vector and estimated severity/impact.
5. Response & Disclosure Timeline
- Initial Acknowledgment: Within 48 business hours of submission.
- Triage & Validation: Within 7 business days, confirming reproduction and assigning a severity rating.
- Remediation Window: We aim to release patched binaries or configuration updates within 30 to 90 calendar days, depending on the severity and complexity of the fix.
- Public Advisory: We will coordinate with the reporting researcher on public release credits and changelog acknowledgments once a patch is distributed.
6. Contact & Legal Entity
ARCA VISION LABS LLC
Austin, TX, United States
Inquiries: observer@arca.vision
Machine-Readable security.txt
This policy is also published as an RFC 9116 security.txt file at /.well-known/security.txt:
Contact: mailto:observer@arca.vision
Contact: mailto:antonio@arca.vision
Expires: 2027-08-27T23:59:59.000Z
Preferred-Languages: en
Canonical: https://www.arca.vision/.well-known/security.txt
Policy: https://www.arca.vision/security
Hiring: https://www.arca.vision/careers