Ethical Research & Safe Harbor
Version: 1.0
•
Effective: 2 September 2026
•
Last Updated: 2 September 2026
Vulnerability Disclosure Policy
ARZAQ INSIGHTS welcomes coordinated security research conducted in good faith. This policy outlines our guidelines for discovering, reporting, and remediating potential security vulnerabilities across our digital ecosystem.
Safe Harbor Commitment:
If you conduct security research in compliance with these guidelines, we will consider your activities authorized and will not pursue legal action or report you to law enforcement regarding your authorized testing.
1. Research Guidelines & Safe Harbor Rules
Security researchers must adhere to the following principles at all times:
- Promptly notify us upon discovering a potential security issue.
- Avoid violating privacy, destroying data, or interrupting platform services.
- Do not perform Denial of Service (DoS/DDoS) attacks or social engineering against employees.
- Only interact with accounts you own or with explicit written consent from the account owner.
- Give our engineering team a reasonable timeframe (minimum 60 days) to resolve issues prior to public disclosure.
2. In-Scope & Out-of-Scope Assets
In-Scope Domains
- •
*.arzaqinsights.com(Web application endpoints) - • Central Authentication & Passkeys API
- • Identity & Account Portal
- • Checkout & Payment Webhook Handlers
Out-of-Scope Activities
- • Physical office security or social engineering / phishing
- • Volumetric DDoS attacks against AWS infrastructure
- • Third-party SaaS providers or Payment Gateway servers
- • Automated vulnerability scanner spam without actionable POC
3. How to Submit a Security Report
Submit detailed vulnerability reports directly to our security engineering team:
Security Email: support@arzaqinsights.com
Subject Format: [Security Vulnerability Report] - Short Description
Required Details: Steps to reproduce, affected URL/endpoint, proof-of-concept (POC) request/response, and assessed impact.
4. Acknowledgment & Hall of Fame
We acknowledge initial reports within 48 hours and provide regular remediation updates. Researchers who adhere to safe harbor guidelines and discover high-impact vulnerabilities may receive public recognition in our Security Hall of Fame.