Safety & community · Revenge Arc policy
Security & Responsible Disclosure
How to report a security concern and the boundaries for responsible vulnerability research.
- Effective
- September 25, 2026
- Last updated
- September 29, 2026
- Version
- 1.2 — owner-confirmed updates; legal review pending
Report a security concern
Send suspected vulnerabilities, unauthorized access, exposed information, credential abuse, or security incidents to revengearchelp@gmail.com with “Security” in the subject. Include the affected URL or feature, date and time, clear reproduction steps, impact, and supporting screenshots or logs with secrets and unrelated personal information removed. Do not send passwords, authentication codes, private keys, full payment-card numbers, or copied user datasets.
Protect people while reporting
- Stop testing when you encounter another person’s data, a secret, destructive behavior, service instability, or a path to material harm.
- Do not access, download, alter, retain, or disclose data beyond the minimum needed to describe the issue.
- Do not disrupt service, perform denial of service, send spam, use malware, extort, threaten, phish, socially engineer, or test physical security.
- Do not test third-party providers, employee accounts, production admin tools, or systems you do not own without their separate written authorization.
- Give us a reasonable opportunity to investigate and reduce risk before public disclosure.
Authorization and safe-harbor limits
This page welcomes good-faith reports but is not blanket authorization to access systems or data. Until Revenge Arc publishes an exact testing scope and safe-harbor commitment approved by security and counsel, limit research to lawful observation and your own accounts and data. If you need testing authorization, request it in writing before testing.
A future program may provide clearer authorized targets, methods, exclusions, disclosure timing, and safe-harbor language. No statement here authorizes conduct prohibited by law or by a third party’s terms.
What to expect
We aim to acknowledge useful reports, assess severity, request clarification when needed, and communicate when a fix or mitigation is available. Acknowledgement, status, remediation, and disclosure timing depend on severity, reproducibility, affected systems, third parties, and legal obligations; no specific response or fix time is promised by this draft.
No bounty or confidentiality promise
Revenge Arc does not currently operate a paid bug-bounty program. A report does not create a right to payment, public credit, employment, or access to confidential remediation details. If you want recognition, say how you would like to be identified, but we may withhold details when disclosure would create risk or violate law or another person’s rights.
User account security
- Use a unique password where a password is offered and protect sign-in links, verification codes, and Apple or Google credentials.
- Keep devices and software updated, review active sessions where available, and sign out of shared devices.
- Contact support promptly if you suspect account takeover, unexpected billing, or disclosure of private content.
- Revenge Arc will never ask you to send a password or authentication code by email.
Questions about this document? Email revengearchelp@gmail.com.
Back to Legal Center