Ark Matter

Security

Reporting a vulnerability

Found a security fault in something we run? Please tell us. This page says where to send it, what happens next, and what we will not do to you for sending it.

Last updated
24 August 2026
Report to
security@arkmatter.uk
Machine-readable
/.well-known/security.txt

In short

Email security@arkmatter.uk with enough detail for us to reproduce it. We will acknowledge within three working days. Report in good faith and we will not come after you for it. There is no bug bounty.

What is in scope

Anything we run:

  • arkmatter.uk — this website.
  • Rilver — rilver.app, its API, and its mobile apps (not yet released, but reports are still welcome).
  • GoGobo — gogobo.app, its API, and its mobile apps.

Out of scope: our suppliers’ own systems. A fault in Cloudflare, Apple, Google or an app store is theirs to fix, and they all run disclosure programmes of their own. If you are not sure which side of the line something falls on, send it anyway and we will tell you.

How to report

Email security@arkmatter.uk. Plain text is fine. The things that help most:

  • Which site, app or endpoint, and the exact URL or version.
  • Steps to reproduce it — the shortest sequence that works.
  • What an attacker gets out of it. That is what sets the priority.
  • Anything you need from us to look further.

Please tell us before you publish, and give us a fair run at fixing it. Ninety days is the usual convention and it is what we plan against. If a fix is going to take longer we will say so and explain why; we will not just go quiet.

If a report involves other people’s personal data, send only what is needed to show the fault. Tell us what else you saw instead of attaching it.

What we do

Acknowledge, within three working days
A person confirming we have it, not an autoresponder. We are small, so three days is what we can honestly promise. It is usually the same day.
Assess, within ten working days
We tell you whether we agree it is a fault, how serious we think it is, and roughly when we expect to have it fixed.
Fix, and tell you
You hear from us when the fix ships. If we decide not to fix something you reported, you get our reasoning instead of silence.
Credit you, if you want it
Say so in your report and we will name you when the fix is announced. If you do not mention it, we will assume you would rather we did not.

If a fault has exposed personal data we will assess it against the UK GDPR breach rules, report it to the ICO within 72 hours where that threshold is met, and tell the people affected where we have to. That runs separately from whatever we agree with you about timing.

What we will not do

Follow this page — report to us, go no further into a system than proving the fault requires, leave other people’s data alone, and hold off publishing until we have had a fair chance to fix it — and we consider your research authorised.

We will not:

  • bring or support a claim against you under the Computer Misuse Act 1990;
  • bring a civil claim against you for the research itself;
  • report you to law enforcement for it;
  • ask your employer, your university or a platform to act against you.

If someone else brings an action against you over research that followed this policy, tell us and we will make clear it was authorised.

This is a commitment from Ark Matter Ltd about our own conduct. It cannot bind anyone else, and it is not legal advice about where you stand.

Please do not

  • Run denial-of-service or load tests, or anything else that makes the service worse for the people using it.
  • Social-engineer our staff, our suppliers or our users, or attempt anything physical.
  • Access, alter, download or keep another person’s data. If you end up in somebody’s account by accident, stop there and tell us what happened.
  • Send us the raw output of an automated scanner. Nobody has confirmed those findings, and working through them takes time away from the real reports.
  • Ask for payment in exchange for the details, or attach a deadline to one. We will treat that as what it is.

Reward

There is no bug bounty and no payment. We are a small company, and we would rather run no programme than one we could not honour.

What you get is a quick reply from a person, a fix, and public credit if you want it. That is the lot, and we would rather you knew before you spent a weekend on it.