Responsible Disclosure Policy
Last updated: June 2025
Our Commitment
Aritaro takes security seriously — both for our clients and for our own systems. We welcome responsible disclosure of security vulnerabilities in our infrastructure and web properties.
Scope
This policy covers aritaro.com and any subdomains or services operated by Aritaro. It does not extend to client systems, which are governed by individual engagement agreements.
How to Report
Send vulnerability reports to security@aritaro.com. Include: (1) Description of the vulnerability, (2) Steps to reproduce, (3) Potential impact, (4) Your contact information. We use PGP for encrypted communication — our public key is available on request.
Our Promise
We will: acknowledge your report within 48 hours, provide an initial assessment within 5 business days, keep you informed of remediation progress, credit you publicly (if desired) once the issue is resolved.
Safe Harbor
We will not take legal action against researchers who: act in good faith, avoid accessing or modifying data belonging to others, do not disrupt our services, report findings promptly and allow reasonable time for remediation.
Out of Scope
The following are generally out of scope: social engineering attacks, denial of service attacks, spam or phishing, issues in third-party services, issues requiring physical access, automated scanner output without a working PoC.
Recognition
We maintain a Hall of Fame for researchers who responsibly disclose valid vulnerabilities. We do not currently operate a paid bug bounty programme, but we provide acknowledgment and reference letters.