Security on Arc

Network-level controls and builder security resources in one place. Evaluate the controls, operators, and third-party services supporting the network — and find the tools, programs, and support available to teams building on Arc.

Third-party monitoring providers
hypernative

Chain-level security

Arc's operating model is built around known participants and defined controls. Review who validates the network, what controls are in place, and which third-party services provide additional visibility.

Known validator operators

Arc is supported by a permissioned validator set of reputable, geographically diverse operators that run consensus under a Proof-of-Authority model.

Network-level sanctions controls

Validator-layer sanctions controls are part of Arc's network operating model, supporting compliance at the infrastructure level.

Deploy more securely

Public resources for deploying on Arc, including technical documentation, predeploy tooling, and technical support — designed to surface potential implementation issues earlier. Start here before you deploy.

Developer docs

Arc-specific implementation considerations and recommended development patterns, so teams know how Arc behaves before deployment.

Arc Studio

Arc Studio enables developers to review their smart contracts for security and Arc-specific checks as they build.

Predeploy tooling

Run Arc-specific checks in Arc Foundry to help surface potential implementation issues before deployment.

Independent monitoring

Third-party providers monitor Arc network activity for additional security visibility. These services are operated by the respective providers.

Technical office hours

Working-level technical support for implementation questions, direct from the Arc team.

Security programs

Arc provides dedicated paths for developers, researchers, and partners to report potential security issues — and financial support for qualifying builders pursuing independent third-party audits.

Audit support

Qualifying Arc builders can access financial support for independent third-party security audits through our Grant Program.1

Arc bug bounties

Security researchers can report qualifying Arc issues and earn up to $1 million.

Report a vulnerability

Developers, researchers, and partners have clear channels for reporting potential security issues to the Arc team.

Submit a bounty report

FAQ

How is Arc secured at the network level?
What security resources are available to developers building on Arc?
What does the predeploy tooling do?
Do Arc-specific security checks mean my application is secure?
Do Arc's security resources replace an independent security audit?
Is audit support available to teams building on Arc?
What role do third-party security providers play?
How can developers or researchers report a potential security issue?

1 Eligibility does not mean Circle has reviewed, approved, or certified an application.

Arc-specific security checks, developer tooling, and other security resources described on this page are intended to help teams identify potential implementation issues. They do not constitute certification, approval, or a guarantee that an application is secure, and they do not eliminate smart contract risk.

Circle does not review or approve every application deployed on Arc. Availability of developer tooling, audit support, or other security resources should not be interpreted as Circle review, approval, certification, or endorsement of any third-party application.

Arc's security resources do not replace independent security review, audits, monitoring, internal controls, or the security responsibilities of application developers and operators.

Third-party monitoring services referenced on this page are operated by the respective third parties.