Orqara
OrqaraResponsible disclosure

Security

If you believe you have found a security issue affecting Orqara, Arc, Arc MCP, or an Orqara-operated service, report it privately to security@orqara.com.

What to include

  • A clear description of the issue and affected component.
  • Steps to reproduce where practical.
  • Expected versus observed behaviour.
  • Relevant version or environment information.
  • Any proof-of-concept material needed to demonstrate impact safely.

Please avoid

  • Accessing data that is not yours beyond what is necessary to demonstrate the issue.
  • Disrupting availability or degrading production services.
  • Publishing exploit details before there has been a reasonable opportunity to investigate and remediate.
  • Sending credentials, private keys, or unrelated private data.

Scope

The public website is live, while Arc and Orqara Cloud remain pre-launch. Reports concerning the website, published documentation, distributed test builds, Arc MCP, or Orqara-operated infrastructure can all use the same security contact.

Contact

Use security@orqara.com for security reports. General product questions should go to support@orqara.com instead.