Responsible disclosure

If you believe you have found a security vulnerability in an Arcophos system, we want to hear about it. This page describes how to report it and what you can expect from us.

Scope

arcophos.com and its subdomains, healthcarereviewer.com and work.healthcarereviewer.com, our benchmark sites, and our public APIs. Vulnerabilities in third-party platforms we use (Vercel, Google Cloud, Cloudflare, GitHub, Stripe, and others) should be reported to those vendors.

How to report

Email info@arcophos.com with the subject “Security vulnerability report”. Include the affected URL or service, steps to reproduce, the impact, and any proof of concept. Our machine-readable contact details are at /.well-known/security.txt.

What we commit to

Please don’t