Supply chain
Packages, CVEs, malicious updates, build tools, and third-party services.
Arc-1 joins the places where your team works. Tag it in Slack. See it review a pull request. Let it handle the first reply to your security inbox. Arc-1 does the work and shows you what it found.
Arc-1 app 8:31 AM
A new unauthenticated RCE affects Metabase. I checked our live inventory. One production service is exposed to the internet.
internet → edge-us → metabase → analytics-db
I blocked the public path. Upgrade PR #391 is open. I am testing the fix now.
Maya 8:34 AM
Great. Did anyone try to use it?
Arc-1 maps what the internet can reach. It connects services, identities, secrets, and data. Hover over a node to inspect its path. Select a node to keep it in view.
It keeps a live map of your software and infrastructure. When new risk appears, Arc-1 finds your exposed path. It contains the risk, makes the fix, and checks the result.
Advisory matched
Arc-1 matches the new RCE to Metabase in the live software inventory.
Exposure found
It traces the public route to analytics-prod and the data behind it.
Risk contained
It removes public access while the team continues to work.
Patch opened
It upgrades the package and opens PR #391 with focused tests.
Fix verified
It tests the attack path again and confirms that the path is closed.
Team updated
It posts the evidence, the change, and the next step in Slack.
Service
analytics-prod
Action
route blocked
Patch
PR #391 ready
Arc-1 keeps these systems current
Packages, CVEs, malicious updates, build tools, and third-party services.
Domains, endpoints, cloud services, open routes, and new public assets.
The real path from the internet to each service, identity, and data store.
Logs, alerts, identity changes, suspicious access, and active incidents.
Package upgrades, safer configuration, focused patches, and proof that the path is closed.
Your team does not need another place to check. Arc-1 works in Slack, GitHub, and email. It gives help where the work happens.
Jordan 2:08 PM
The auth service is live. Let us know if you see anything.
Arc-1 app
I checked the release. The new endpoint is safe. I also found an old admin route that is still public. I opened a fix.
✓ Helpful 4Arc-1 can reply without a tag
arc-1 reviewed 2 minutes ago
Change requested
src/webhooks/verify.ts · line 48
The retry path uses the event before it checks the signature. I sent a forged event to the test route and confirmed the write. Move verification above the parser.
The issue includes a tested fix
Incoming report
Possible account takeover
A researcher sent three steps and a screen recording. Arc-1 compared the report with the current product.
Arc-1
to researcher · 6 minutes ago
Thanks for the clear report. I reproduced the issue on a test account. The session stays valid after the email change. We marked this as high impact and sent it to the owner. We will update you when the fix is ready.
Arc-1 maps the system, proves each path, and closes real risk. It then starts again. The same graph stays current as your system changes.
Arc-1 builds a live graph of domains, services, cloud assets, identities, secrets, and third-party systems. It connects each item to the system around it.
Arc-1 tests each possible path. It checks the full chain in a safe way. Failed paths leave the graph. Proven paths stay with clear evidence.
Arc-1 contains the risk and prepares the fix. It then tests the path again. A new deploy or service starts the loop again.
Arcsec Labs helps product teams in San Francisco and beyond. We test real systems. We prove what an attacker can reach. We help the team close the path.
Product teams use Arcsec Labs to test their live systems.
We found and proved a real path in each of these environments.
We do not call an issue critical until we can prove the path.
Each confirmed result includes the exact path and the evidence.
selected work · details are available in a call
Attackers can use machines to explore, retry, and chain weak paths at high speed. They do not wait for office hours or the next audit.
A weak package can lead to a service. A service can lead to a secret. A secret can lead to your data. Your defender must see and close the full path.
A machine can test the next path while your team is offline.
It can run probes, pivots, and exploit attempts in parallel.
One missed path can be enough to reach a critical system.
Arc-1 works at machine speed too. It maps, checks, contains, and fixes.
Arcsec Labs
The lab behind Arc-1
Arcsec Labs helps leading product teams in San Francisco and beyond. We find hard security flaws. We prove the impact. We help teams fix the path. We built that way of working into Arc-1.
Selected research
Each result below used a safe proof. We kept confirmed impact separate from possible impact.
We found a deterministic path from untrusted JavaScript to the host process. It worked in all ten tests on both default sandbox APIs.
confirmed · controlled proof
We traced customer input to command execution in a production parser. The normal result API returned the operating system proof.
confirmed · end to end
We confirmed that an attached agent could read outside its allowed folder on a real Mac. The file tool blocked the path. The command tool did not.
confirmed · safe marker
Arc-1 is ready to help
Tell us what your team builds. Tell us where security takes too much time. We will show you how Arc-1 can help.