OrqaraResponsible disclosure
Security
If you believe you have found a security issue affecting Orqara, Arc, Arc MCP, or an Orqara-operated service, report it privately to security@orqara.com.
What to include
- A clear description of the issue and affected component.
- Steps to reproduce where practical.
- Expected versus observed behaviour.
- Relevant version or environment information.
- Any proof-of-concept material needed to demonstrate impact safely.
Please avoid
- Accessing data that is not yours beyond what is necessary to demonstrate the issue.
- Disrupting availability or degrading production services.
- Publishing exploit details before there has been a reasonable opportunity to investigate and remediate.
- Sending credentials, private keys, or unrelated private data.
Scope
The public website is live, while Arc and Orqara Cloud remain pre-launch. Reports concerning the website, published documentation, distributed test builds, Arc MCP, or Orqara-operated infrastructure can all use the same security contact.
Contact
Use security@orqara.com for security reports. General product questions should go to support@orqara.com instead.