Help us protect our users. We reward security researchers who responsibly disclose vulnerabilities.
We're particularly interested in the following types of vulnerabilities:
Bypasses, session management flaws
Privilege escalation, IDOR
Information disclosure, sensitive data leaks
SQL injection, XSS, command injection
Cross-site request forgery
SSRF, XXE, remote code execution
Minor security issues with limited impact
Moderate security vulnerabilities
Significant security issues
Note: Reward amounts are determined based on severity, impact, and quality of the report. Final amounts are at Archways' discretion.
Send your vulnerability report to our security team with the following information:
Clear explanation of the security issue
What an attacker could do with this vulnerability
Step-by-step instructions to reproduce the issue
Screenshots, videos, or code demonstrating the vulnerability
Response Time: We aim to acknowledge reports within 48 hours and provide initial assessment within 5 business days.
Email our security team with your findings. We appreciate your help in keeping Archways secure.
Last updated: October 2025