Trust

Security at Arcsec

Last updated July 2026


We build a platform that finds the way into other people's systems. We hold our own to the same standard. This page describes how we think about the security of Arcsec itself and how to reach us if you find something.

Our posture

Arcsec operates on the assumption that any component can be compromised and designs to contain the blast radius when one is. In practice that means least-privilege access throughout, network segmentation between environments, short-lived credentials with automatic rotation, and isolation of any workload that processes untrusted input.

Handling customer data

Assessment data describes your exposure, so we treat it as sensitive by default. Findings are encrypted in transit and at rest, access is scoped and logged, and we retain only what a given engagement requires. We'll walk through the specifics (data flows, retention, and residency) as part of any evaluation.

Reporting a vulnerability

If you believe you've found a security issue in Arcsec, we want to hear from you. Email hello@arcseclabs.com with enough detail to reproduce the issue. We'll acknowledge your report, keep you updated as we investigate, and we won't pursue action against good-faith research conducted under this policy.

Responsible testing

When acting on your behalf, Arcsec tests only assets you authorize, within the scope you define, and in a way designed to validate exposure without causing harm. Scope and rules of engagement are agreed before any testing begins.

This page describes our current practices and will evolve as the platform does. It is not a contract; specific commitments are covered in your agreement with Arcsec Labs Inc..