ArcSim Security
Responsible Vulnerability Disclosure Program

ArcSim Security Policy & Compliance Standards

At ArcSim, the security and mathematical integrity of our power engineering simulation platform are of paramount importance. We maintain a robust, trustworthy environment and welcome responsible security research from the global community.

Platform Architecture & Scope

ArcSim operates on a Local-First, Client-Side execution model. Electrical network matrices, impedance networks, short-circuit currents, and arc flash calculations are performed entirely inside the user's browser runtime. No electrical system models, single-line diagrams, or confidential facility parameters are transmitted to or stored on remote application servers.

In-Scope Targets:
  • https://arcsim.info/*
  • Static web application assets and service worker manifests
  • Mathematical numerical stability and injection resistance

Reporting a Vulnerability

If you discover a security vulnerability or critical issue, please report it immediately to our security response team:

Security Contact: [email protected]
Alternative: https://arcsim.info/#contact
Response SLA: Acknowledgment within 48 business hours

Please include clear steps to reproduce, affected components, and potential impact. Do not publicly disclose any issue until a fix has been verified and deployed.

Safe Harbor & Research Guidelines

We consider security research conducted under this policy to be authorized. We commit not to initiate legal action against researchers who:

  • Make a good faith effort to avoid privacy violations, data destruction, or service interruptions.
  • Do not execute Denial of Service (DoS/DDoS) attacks against our infrastructure.
  • Do not perform social engineering, phishing, or spam attacks against team members or users.
  • Give our engineering team reasonable time to investigate and remediate reported findings before any public disclosure.
Last Updated: September 28, 2026 • ArcSim Power Systems Security & Compliance Team