Skip to content

Security: virtualmase/arctura.network

Security

SECURITY.md

Security policy

Reporting a vulnerability

Send vulnerability reports privately to ops@arm-agency.com, Arctura Network's delegated DevOps provider. Do not open a public issue for an unpatched vulnerability or include credentials, private data, wallet material, or exploit details in repository discussions.

Include:

  • the affected URL, file, release, or component;
  • the observed behavior and expected boundary;
  • minimal reproduction steps;
  • likely impact;
  • any temporary mitigation already applied;
  • a safe way to contact you.

ARM Agency will coordinate infrastructure triage under Arctura Network direction, establish a private review record, and publish verified remediation information when disclosure is safe. This policy does not promise a bounty or a fixed response time.

Scope

The public website, published schemas, repository automation, and Arctura-maintained prototypes are in scope. Third-party platforms, Hostinger, Cloudflare, GitHub, Bittensor, and unrelated Arctura-named projects remain governed by their own security programs.

Safe handling

Do not access data that is not yours, interrupt service, send unsolicited traffic, test social engineering, or retain sensitive material. Stop once you have enough evidence to explain the issue safely.

There aren't any published security advisories