Skip to content
Geocentric
ModelsTechnologySafetyCompanyNewsCareers
Try Arc

Legal

Security and Vulnerability Disclosure

Last updated: 9 September 2026

What this means

If you find a security problem in our sites or services, please tell us. We would much rather hear it from you than read about it later.

We will not pursue legal action against good-faith research that follows this policy. We do not currently run a paid bug bounty, so we cannot promise a reward — but we will credit you if you want the credit.

On this page

Reporting a vulnerabilityScopeWhat we ask of researchersWhat we commit toOur own practices

Reporting a vulnerability

Send reports to contact@geocentricai.com. Please include what you found, where, the steps to reproduce it, and your assessment of the impact. A proof of concept helps.

We aim to acknowledge a report within three business days and to keep you informed while we work on it. If you have not heard back, please chase us rather than assume the report was ignored.

Scope

In scope: geocentricai.com, chat.geocentricai.com, and the model-serving endpoints behind the chat interface.

Out of scope: reports generated solely by automated scanners without demonstrated impact, missing security headers with no exploitable consequence, social engineering of our staff, physical attacks, and denial-of-service testing. Reports that a model produced incorrect, offensive, or unexpected text are model behaviour rather than security vulnerabilities — those are interesting to us, but send them to contact@geocentricai.com instead.

What we ask of researchers

  • Do not access, modify, or retain other people's data. If you encounter someone else's data, stop and tell us.
  • Do not run destructive tests, and do not degrade or disrupt the service for others.
  • Keep the volume of automated testing low enough that it does not amount to a denial-of-service.
  • Give us a reasonable opportunity to fix the issue before disclosing it publicly. We suggest 90 days, and we are happy to discuss a different timeline for a complex issue.
  • Do not use a vulnerability to extract model weights or proprietary material beyond what is needed to demonstrate the problem.

What we commit to

If you follow this policy in good faith, we will treat your research as authorised conduct. We will not initiate legal action against you, and we will not report you to law enforcement for that research. If a third party brings action against you for research conducted in accordance with this policy, we will make it known that your activity was authorised.

We will tell you what we found, what we fixed, and when. If you would like public credit, we will give it. We do not currently operate a paid bounty programme, and we will say so plainly rather than imply a reward that does not exist.

Our own practices

A short and deliberately non-specific summary: both sites are served over HTTPS behind Cloudflare. The chat service sets a restrictive Content Security Policy limiting scripts, styles and network connections to its own origin, sends no referrer, denies framing, and disables MIME sniffing. It stores no credentials, because it has none to store, and it holds conversation history on the user's device rather than on our servers.

We do not publish details of our internal security controls or infrastructure, because doing so would weaken them without helping anyone acting in good faith.

Models

Model family Arc model card Try Arc

Research

Technology EPICYCLE PARALLAX Training data

Company

About Safety News Careers Contact

Legal

Legal hub Terms of Service Privacy Policy Acceptable Use AI disclosure Security Consent settings
Geocentric © Geocentric Measure first.