Responsible Vulnerability Disclosure
Last updated: 24 August 2026
Purpose
We welcome good-faith reports that help protect Arad customers, users and systems.
In scope
Report reproducible vulnerabilities in publicly reachable Arad-owned web applications or APIs. Confirm ownership before testing. Customer environments, third-party services, social engineering, denial of service and physical attacks are out of scope unless expressly authorized.
Safe research
Use the minimum testing needed to demonstrate impact. Do not access more data than necessary, alter or delete information, maintain persistence, disrupt availability, automate high-volume traffic or disclose a finding before remediation coordination.
Reporting
Submit a Contact request through the secure inquiry form with “Security vulnerability” in the subject or message. Include affected URL, steps, impact, evidence, test account and preferred contact details. Do not include unnecessary personal data or live secrets.
Our response
We aim to acknowledge credible reports within two business days, triage severity, maintain reasonable communication and coordinate remediation and disclosure. Timelines depend on complexity and risk.
Good-faith assurance and rewards
When research follows this policy, we will not intentionally pursue action solely for the compliant testing. This statement does not authorize unlawful activity or bind third parties. No bounty or reward is promised unless agreed in writing.
