Security on Arc
Network-level controls and builder security resources in one place. Evaluate the controls, operators, and third-party services supporting the network — and find the tools, programs, and support available to teams building on Arc.

Chain-level security
Arc's operating model is built around known participants and defined controls. Review who validates the network, what controls are in place, and which third-party services provide additional visibility.
Arc is supported by a permissioned validator set of reputable, geographically diverse operators that run consensus under a Proof-of-Authority model.
Validator-layer sanctions controls are part of Arc's network operating model, supporting compliance at the infrastructure level.
Security programs
Arc provides dedicated paths for developers, researchers, and partners to report potential security issues — and financial support for qualifying builders pursuing independent third-party audits.
Qualifying Arc builders can access financial support for independent third-party security audits through our Grant Program.1
Security researchers can report qualifying Arc issues and earn up to $1 million.
Report a vulnerability
Developers, researchers, and partners have clear channels for reporting potential security issues to the Arc team.
FAQ
1 Eligibility does not mean Circle has reviewed, approved, or certified an application.
Arc-specific security checks, developer tooling, and other security resources described on this page are intended to help teams identify potential implementation issues. They do not constitute certification, approval, or a guarantee that an application is secure, and they do not eliminate smart contract risk.
Circle does not review or approve every application deployed on Arc. Availability of developer tooling, audit support, or other security resources should not be interpreted as Circle review, approval, certification, or endorsement of any third-party application.
Arc's security resources do not replace independent security review, audits, monitoring, internal controls, or the security responsibilities of application developers and operators.
Third-party monitoring services referenced on this page are operated by the respective third parties.
