Back to Arniqo
Security
Security is built into how Arniqo designs, engineers, and operates. This page outlines our approach and how to report a concern.
Our practices
- Encryption - data is encrypted in transit (TLS) and, where applicable, at rest.
- Access control - access to systems and data is limited to those who need it, under the principle of least privilege.
- Secure development - code review, dependency monitoring, and testing are part of our delivery process.
- Monitoring - we log and monitor systems to detect and respond to unusual activity.
Reporting a vulnerability
If you believe you have found a security vulnerability, please report it through our contact form. Include enough detail for us to reproduce and verify the issue. We ask that you give us a reasonable time to respond before any public disclosure.
Scope
Please do not attempt to access, modify, or destroy data that is not yours, degrade our services, or use social engineering against our team. Good-faith research within these bounds is welcome.
Contact
For any security question, reach us through ourcontact form.