The security teammatewho is already on it.

Arc-1 joins the places where your team works. Tag it in Slack. See it review a pull request. Let it handle the first reply to your security inbox. Arc-1 does the work and shows you what it found.

watches for new riskacts with evidencekeeps the team informed
Slack · #security-incidents Arc-1 started a thread

Arc-1 app 8:31 AM

A new unauthenticated RCE affects Metabase. I checked our live inventory. One production service is exposed to the internet.

analytics-prod · exposedCritical

internet → edge-us → metabase → analytics-db

I blocked the public path. Upgrade PR #391 is open. I am testing the fix now.

Maya 8:34 AM

Great. Did anyone try to use it?

No matching activity in the last 30 days.
Watching without a tag
Slack · GitHub · Email
Arc-1 · live system map

See the path before it becomes an incident.

Arc-1 maps what the internet can reach. It connects services, identities, secrets, and data. Hover over a node to inspect its path. Select a node to keep it in view.

Interactive exposure map Arc-1 is mapping
path proveninternet → staging → ci-runner → deploy-bot → customer-db
  1. staging.arcsec.io · waf absent, basic-auth disabled
  2. ci-runner-04 · build hijack via docker.sock
  3. iam::deploy-bot · AdministratorAccess assumed
  4. rds::customer-db · 2.1M records readable
Proactive by default

Arc-1 keeps your supply chain and exposure in view.

It keeps a live map of your software and infrastructure. When new risk appears, Arc-1 finds your exposed path. It contains the risk, makes the fix, and checks the result.

Example response · Metabase RCEResolved in 23 min
08:31

Advisory matched

Arc-1 matches the new RCE to Metabase in the live software inventory.

08:32

Exposure found

It traces the public route to analytics-prod and the data behind it.

08:34

Risk contained

It removes public access while the team continues to work.

08:41

Patch opened

It upgrades the package and opens PR #391 with focused tests.

08:53

Fix verified

It tests the attack path again and confirms that the path is closed.

08:54

Team updated

It posts the evidence, the change, and the next step in Slack.

Live infrastructure graph path blocked
The public path through edge-us to the affected Metabase service is blocked

Service

analytics-prod

Action

route blocked

Patch

PR #391 ready

Arc-1 keeps these systems current

01

Supply chain

Packages, CVEs, malicious updates, build tools, and third-party services.

02

Live exposure

Domains, endpoints, cloud services, open routes, and new public assets.

03

Infrastructure graph

The real path from the internet to each service, identity, and data store.

04

Activity

Logs, alerts, identity changes, suspicious access, and active incidents.

05

Fixes

Package upgrades, safer configuration, focused patches, and proof that the path is closed.

A teammate, not a dashboard

Arc-1 is part of the conversation.

Your team does not need another place to check. Arc-1 works in Slack, GitHub, and email. It gives help where the work happens.

Slack#engineering
JR

Jordan 2:08 PM

The auth service is live. Let us know if you see anything.

A1

Arc-1 app

I checked the release. The new endpoint is safe. I also found an old admin route that is still public. I opened a fix.

✓ Helpful 4

Arc-1 can reply without a tag

GitHubPull request #284
A1

arc-1 reviewed 2 minutes ago

Change requested

src/webhooks/verify.ts · line 48

The retry path uses the event before it checks the signature. I sent a forged event to the test route and confirmed the write. Move verification above the parser.

+ verifySignature(rawBody, signature)

The issue includes a tested fix

Gmailsecurity@company.com Arc-1 replied

Incoming report

Possible account takeover

A researcher sent three steps and a screen recording. Arc-1 compared the report with the current product.

Valid · High impact
A1

Arc-1

to researcher · 6 minutes ago

Thanks for the clear report. I reproduced the issue on a test account. The session stays valid after the email change. We marked this as high impact and sent it to the owner. We will update you when the fix is ready.

owner assignedfix trackedreporter updated
Recon · how it works

One continuous loop.It does not stop at a report.

Arc-1 maps the system, proves each path, and closes real risk. It then starts again. The same graph stays current as your system changes.

01map

Map everything an attacker can see

Arc-1 builds a live graph of domains, services, cloud assets, identities, secrets, and third-party systems. It connects each item to the system around it.

external + internalcloud assetsleaked secretsthird-party
map
13 entities · 12 edges · expanded from one seed domain
02validate

Prove what is reachable

Arc-1 tests each possible path. It checks the full chain in a safe way. Failed paths leave the graph. Proven paths stay with clear evidence.

full chain replayno false positivessafe execution
validate
1 of 9 candidate paths proved reachable · 4 disproved
03defend

Close the path and keep watching

Arc-1 contains the risk and prepares the fix. It then tests the path again. A new deploy or service starts the loop again.

path severedfix verifiedre-maps on change
defend
path severed at ci-runner-04 · target contained · re-scanning
defendre-map · continuously
In the field

Real findings from real systems.

Arcsec Labs helps product teams in San Francisco and beyond. We test real systems. We prove what an attacker can reach. We help the team close the path.

0+
enterprise pilots

Product teams use Arcsec Labs to test their live systems.

0+
teams with real findings

We found and proved a real path in each of these environments.

0
unproved criticals

We do not call an issue critical until we can prove the path.

0%
findings with a path

Each confirmed result includes the exact path and the evidence.

selected work · details are available in a call

Why now

The attacker is nowa machine.

Attackers can use machines to explore, retry, and chain weak paths at high speed. They do not wait for office hours or the next audit.

A weak package can lead to a service. A service can lead to a secret. A secret can lead to your data. Your defender must see and close the full path.

0/7active

A machine can test the next path while your team is offline.

0sof actions

It can run probes, pivots, and exploit attempts in parallel.

0open path

One missed path can be enough to reach a critical system.

Arc-1 works at machine speed too. It maps, checks, contains, and fixes.

Arcsec Labs

The lab behind Arc-1

Arc-1 comes from real security work.

Arcsec Labs helps leading product teams in San Francisco and beyond. We find hard security flaws. We prove the impact. We help teams fix the path. We built that way of working into Arc-1.

Selected research

The proof is in the work.

Each result below used a safe proof. We kept confirmed impact separate from possible impact.

Sandbox research

10 out of 10

We found a deterministic path from untrusted JavaScript to the host process. It worked in all ten tests on both default sandbox APIs.

confirmed · controlled proof

Production worker

Live RCE

We traced customer input to command execution in a production parser. The normal result API returned the operating system proof.

confirmed · end to end

Agent boundary

Root escaped

We confirmed that an attached agent could read outside its allowed folder on a real Mac. The file tool blocked the path. The command tool did not.

confirmed · safe marker

Arc-1 is ready to help

Add a diligent security teammate.

Tell us what your team builds. Tell us where security takes too much time. We will show you how Arc-1 can help.