Page

Responsible Vulnerability Disclosure

How security researchers can report potential vulnerabilities to Arad ITC safely and responsibly.

Responsible Vulnerability Disclosure

Last updated: 24 August 2026

Purpose

We welcome good-faith reports that help protect Arad customers, users and systems.

In scope

Report reproducible vulnerabilities in publicly reachable Arad-owned web applications or APIs. Confirm ownership before testing. Customer environments, third-party services, social engineering, denial of service and physical attacks are out of scope unless expressly authorized.

Safe research

Use the minimum testing needed to demonstrate impact. Do not access more data than necessary, alter or delete information, maintain persistence, disrupt availability, automate high-volume traffic or disclose a finding before remediation coordination.

Reporting

Submit a Contact request through the secure inquiry form with “Security vulnerability” in the subject or message. Include affected URL, steps, impact, evidence, test account and preferred contact details. Do not include unnecessary personal data or live secrets.

Our response

We aim to acknowledge credible reports within two business days, triage severity, maintain reasonable communication and coordinate remediation and disclosure. Timelines depend on complexity and risk.

Good-faith assurance and rewards

When research follows this policy, we will not intentionally pursue action solely for the compliant testing. This statement does not authorize unlawful activity or bind third parties. No bounty or reward is promised unless agreed in writing.