How to report
Email mostafa@openarche.org with “Private ARCHE security report” in the subject. Include the affected URL, impact, reproduction steps and any safe supporting evidence. Do not include passwords, access tokens or unrelated personal data.
Safe research
Use only accounts and data you own or have explicit permission to test. Avoid privacy violations, service disruption, data destruction, automated traffic that affects availability, social engineering and public disclosure before remediation.
What to expect
ARCHE will acknowledge a complete report when operationally possible, preserve relevant audit records, assess impact and communicate remediation status. Reports are handled on a best-effort basis during this early-stage release; no bounty or payment is promised.
Operational controls
Production uses verified account sessions, rate limits, TLS PostgreSQL, hashed passwords, single-use verification/reset tokens, human-only governance controls and auditable AI Agent execution boundaries. Sensitive credentials belong only in encrypted hosting configuration.
Incident priorities
Credential exposure, unauthorized governance actions, private-data disclosure, Agent impersonation, audit-record tampering and loss of canonical engineering provenance are treated as high-priority incidents.