Report a Security or Privacy Concern

Esri maintains a single intake point for reporting security vulnerabilities, privacy concerns, security assurance, and compliance questions relating to Esri products, services, and corporate operations. It is not a technical support channel. To help us route and respond quickly, please select the category that best matches your concern as defined below and provide all applicable information in the reporting form, including sufficient details of your specific concern. Your contact details will only be used to follow up on the information you provide.

  • Vulnerability / Security Concern - Report a vulnerability found in ArcGIS Online or any Esri product, or report abuse of the Esri brand, including misleading domains purported to be linked to Esri, providers of cracked Esri software, or phishing sites targeting Esri customers or employees.
  • Privacy Concern (Product) – Report a privacy concern related to our applications or products, such as ArcGIS Online or any other Esri product. Use this if you have a question or concern about data collection, use, retention, or protection within a product experience.
  • Privacy Concern (DSAR, Corporate) - Submit a Data Subject Access Request (DSAR) or if you have a privacy concern related to our organization, such as marketing materials or the Esri.com corporate website.
  • Other (Compliance or Assurance questions) - For all other security, privacy, or compliance-related concerns, including WAF guidance, antivirus, the Enterprise Hardening Guide, Software Assurance Agreement (SAA), as well as questions about certifications and compliance programs like FedRAMP, ISO, SOC, and others.

If you believe you are experiencing an active security incident in your own environment, contact Esri Technical Support in parallel with this form so your case can be escalated immediately.


What happens after you submit

  1. Acknowledgment. You receive an automated confirmation immediately, followed by a human acknowledgment with a tracking reference.
  2. Triage and routing. Your submission is assigned to PSIRT, Security, Privacy, or the Compliance team, and assessed for severity and urgency. If we need more information before we can proceed, we will ask at this stage.
  3. Investigation. We reproduce and validate the finding, or research the privacy or compliance question. Product-level issues may require engineering involvement. This is normally the longest stage.
  4. Resolution. This may be remediation (a patch, configuration change, documentation update, or takedown) or a substantive written answer, or an explanation of why we assessed the issue differently than you did. You will hear the outcome either way.
  5. Disclosure and closure. For validated vulnerabilities, Esri publishes a security advisory and CVE where applicable, and notifies you when a fix is available.

You will hear from us at each transition. If you have not, reply to your acknowledgment with the tracking reference.
Subscribe to the Trust Announcement RSS feed to be notified of patches, advisories, and other trust topics.

How Esri handles the information you submit

  • Contact details are used only to follow up on your submission.
  • Submissions are accessible to the Esri personnel handling them and, where necessary to resolve the issue, to the relevant product or engineering teams.
  • Vulnerability details are treated as confidential until a fix is available and coordinated disclosure has occurred.
  • Submissions are retained in accordance with Esri's retention schedule for security and privacy case records.
  • Esri's Privacy Statement governs the handling of personal information you provide here.


Encrypted Communication

Esri PSIRT provides a public PGP key for use when communicating with our team. Please make use of this key when providing details of software vulnerabilities to Esri.


Vulnerability Reporting Policy

The Esri Product Security Incident Response Team (PSIRT) acknowledges the valuable role that independent security researchers play in Internet security. We encourage responsible reporting of any vulnerabilities that may be found in our site or application.
Esri is committed to working with the security community to verify and respond to any potential vulnerabilities that are reported to us.

Safe Harbor

Esri will not pursue legal action against, or refer for law enforcement investigation, a researcher who acts in good faith and complies with this policy. Research conducted in good faith under this policy is not treated as a violation of Esri's terms of use. This protection does not extend to activity directed at systems or data belonging to Esri customers or other third parties, which Esri has no authority to authorize.

Esri does not permit the following types of security research

  • Causing, or attempting to cause, a Denial of Service (DoS) condition.
  • Use automated security tools without Esri's explicit consent. Use of automated tools may result in investigative action or your IP(s) being blocked.
  • Accessing, or attempting to access, data or information that does not belong to you.
  • Destroying or corrupting, or attempting to destroy or corrupt, data or information that does not belong to you.
  • Social engineering of Esri personnel, customers, or partners, including phishing and pretexting.
  • Physical attacks against Esri facilities or personnel.
  • Retaining, transmitting, or publishing personal information encountered during research.
  • Publicly disclosing a vulnerability before coordinated disclosure has been agreed.

Vulnerability Reporting Requirements

  • Esri offers a Coordinated Vulnerability and Disclosure program.
  • Our program requirements are documented here.
  • Vulnerability reports that do not meet these requirements are rejected.
  • Please review our requirements prior to reporting vulnerability concerns to Esri.

Researchers, Root and Sub CNAs:

  • Esri is the CVE Numbering Authority (CNA) of record for the scope of Esri Software products.
  • Esri assigns CVE identifiers for vulnerabilities following coordinated vulnerability disclosure guidelines.
  • Esri will publish advisories for vulnerabilities when patches that address the vulnerability identified are available.
  • Patches are provided for software in General availability and Extended support under Esri’s product life cycle.
  • Patches are not provided for software in mature support or retired status.
  • Customers using software in mature or retired status should upgrade to a current software version to remediate security vulnerabilities that are patched in accordance with Esri’s product life cycle.

Third Party Component Vulnerabilites


The Esri Product Security Incident Response Team commitment

To all security researchers who follow this Vulnerability Reporting Policy, the Product Security Incident Response Team commits the following:

  • We will immediately acknowledge receipt of your report and provide a PSIRT ticket ID.
  • We will validate the reported issue and provide next steps.
  • We will provide an estimated time frame for addressing this vulnerability.
  • We will notify the reporting individual when the vulnerability has been fixed.
  • If a valid vulnerability in Esri code is confirmed, we will register a CVE after a fix is provided.
  • We will credit researchers in our acknowledgments list, if you would like to be credited.