Law / United States / Arizona
Unauthorized release of proprietary or confidential computer security information
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not communicate, release, or publish proprietary or confidential security information, security-related measures, algorithms, or encryption devices specific to a particular computer, system, or network without that system's owner's or operator's authorization.
- Publishing a security warning or defect information that is not specific to a particular owner's or operator's system, sharing security information among that system's own authorized users, notifying an owner or operator of a perceived threat, or non-target-specific security research, development, or testing is exempt.
- Security research that discloses findings specific to a particular target's own system is not exempt merely because it arose from otherwise-lawful access or legitimate research.
If you get it wrong
Criminal exposureYes
Criminal exposure note
A class 6 felony, or a class 4 felony where the security information relates to a critical infrastructure resource.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Makes it unlawful to communicate, release, or publish proprietary or confidential computer security information, security-related measures, algorithms, or encryption devices relating to a particular computer, system, or network, without the authorization of that system's owner or operator.
Exemptions cover releasing a security warning or defect information that is not specific to a particular owner's or operator's system, sharing security information among a system's own authorized users, notifying an owner or operator of a perceived threat, and research, development, or testing of security measures that is likewise not specific to a particular owner's or operator's system.
A scraper or security researcher who discovers and publishes a vulnerability specific to one operator's own system, rather than a generic product defect, is not exempted merely because the underlying access was otherwise lawful.
When LexLint raises it
crawls_web
Read the law
official Arizona Revised Statutes text, Arizona State Legislature website