Responsible disclosure
If you believe you have found a security vulnerability in an Arcophos system, we want to hear about it. This page describes how to report it and what you can expect from us.
Scope
arcophos.com and its subdomains, healthcarereviewer.com and work.healthcarereviewer.com, our benchmark sites, and our public APIs. Vulnerabilities in third-party platforms we use (Vercel, Google Cloud, Cloudflare, GitHub, Stripe, and others) should be reported to those vendors.
How to report
Email info@arcophos.com with the subject “Security vulnerability report”. Include the affected URL or service, steps to reproduce, the impact, and any proof of concept. Our machine-readable contact details are at /.well-known/security.txt.
What we commit to
- Acknowledge your report within 3 business days and complete an initial assessment within 10.
- Fix confirmed issues on a severity-based timeline (critical issues within 72 hours) and tell you when done.
- Credit you, if you wish, once the issue is resolved. We do not currently run a paid bounty program.
- Safe harbor: we will not pursue legal action against researchers acting in good faith under this policy.
Please don’t
- Run denial-of-service or resource-exhaustion tests, or automated scanning that degrades service.
- Access, modify, or retain data beyond what is needed to demonstrate the issue — and report any accidental access to personal or health data immediately.
- Phish or socially engineer our staff or contractors, or attempt physical access to our facilities.
- Test against accounts you do not own.