We ask customers to let us examine their controls. It would be poor form not to say how ours work. This page describes how ArcLight6 handles controlled information, who has access to it, how we treat vendors, and what happens when something goes wrong.
A security posture page that nobody has re-read in two years is worse than none, so the review date is stated plainly. If it looks stale, treat it as stale and ask us.
If you have found a vulnerability in this website or in anything else we run, we want to hear about it before someone else finds it. Report it to security@arclight6.com. Tell us what you found and how to reproduce it; give us a reasonable window to fix it before publishing.
We do not run a paid bug bounty. We will acknowledge your report, keep you updated while we fix it, and credit you if you would like to be credited. Machine-readable contact details are published at /.well-known/security.txt.Confirm security@ address exists and is monitored