Skip to main content
ARCHE3
Public Prototype · Demo Data Enabled

Security policy · Version 1

Security and responsible disclosure

Report security concerns privately so they can be investigated without exposing contributors, credentials or engineering records.

How to report

Email mostafa@openarche.org with “Private ARCHE security report” in the subject. Include the affected URL, impact, reproduction steps and any safe supporting evidence. Do not include passwords, access tokens or unrelated personal data.

Safe research

Use only accounts and data you own or have explicit permission to test. Avoid privacy violations, service disruption, data destruction, automated traffic that affects availability, social engineering and public disclosure before remediation.

What to expect

ARCHE will acknowledge a complete report when operationally possible, preserve relevant audit records, assess impact and communicate remediation status. Reports are handled on a best-effort basis during this early-stage release; no bounty or payment is promised.

Operational controls

Production uses verified account sessions, rate limits, TLS PostgreSQL, hashed passwords, single-use verification/reset tokens, human-only governance controls and auditable AI Agent execution boundaries. Sensitive credentials belong only in encrypted hosting configuration.

Incident priorities

Credential exposure, unauthorized governance actions, private-data disclosure, Agent impersonation, audit-record tampering and loss of canonical engineering provenance are treated as high-priority incidents.