Security & Vulnerability Disclosure
Effective: July 13, 2026 · Last updated: July 13, 2026
Reporting a Vulnerability
If you believe you have found a security vulnerability in Archive, please tell us at support@archiveledger.com with the subject line "Security". Include enough detail for us to reproduce the issue: the affected URL or endpoint, the steps you took, what you observed, and — if you have one — a proof of concept. If the issue is sensitive, say so and we will arrange a secure channel. We will acknowledge your report within three business days, keep you informed as we investigate, and tell you when the issue is resolved.
Good-Faith Research: Our Commitment to You
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you related to it. If a third party brings legal action against you for research you conducted in accordance with this policy, we will make it known that your actions were authorized.
Rules of Engagement
Please: test only against your own account and your own data; stop as soon as you have confirmed a vulnerability, and do not go further into a system than is necessary to demonstrate it; do not access, modify, download, or delete any other customer's data; do not degrade the service (no denial-of-service, no load testing, no spam); do not use social engineering, phishing, or physical attacks; and give us reasonable time to remediate before disclosing publicly. Do not exfiltrate data. If you inadvertently encounter customer data, stop, do not save it, and tell us immediately.
Scope
In scope: archiveledger.com and the Archive application. Out of scope: findings that require physical access to a device or a compromised account; reports from automated scanners without a demonstrated exploit; missing best-practice headers with no demonstrated impact; social-engineering and phishing attacks; and vulnerabilities in third-party services we use, which should be reported to those providers directly (we are happy to help route them).
Recognition
Archive does not currently operate a paid bug-bounty program. We do credit researchers who report valid issues, with your permission, and we are grateful for the work.
Contact
support@archiveledger.com — Archive Ledger, Inc., 910 W Pierce St, Ste 2035, Carlsbad, NM 88220.