🛡️

Report a Vulnerability

We value responsible disclosure. If you've discovered a security issue in our systems, please report it through this secure channel. Your efforts help keep our readers' data safe.

Program Scope

We welcome reports for the following assets. Out-of-scope items are listed for clarity.

In Scope

  • aevumnews.com (all subdomains)
  • Reader accounts & authentication flows
  • Payment processing & subscription endpoints
  • APIs & developer portals
  • Mobile applications (iOS & Android)
  • Publicly documented cloud infrastructure

Out of Scope

  • DoS/DDoS or brute force attacks
  • Social engineering or phishing attempts
  • Automated scanner reports without proof
  • Issues on third-party services we don't control
  • Content manipulation or SEO spam
  • Missing security headers with no impact

Submit a Report

All submissions are encrypted and reviewed by our security engineering team.

We'll only use this for response communication.

Do not include personally identifiable information of readers or internal staff.

✓ Report Received Successfully

Your submission has been encrypted and queued for review. You will receive a confirmation email within 24 hours with a tracking ID.

Our Process & Timeline

We follow industry-standard responsible disclosure practices.

1

Acknowledgment

Within 24 hours, you'll receive a confirmation email with a unique tracking reference.

2

Triaging & Validation

Our security team validates the report, reproduces the issue, and assesses severity.

3

Remediation

We develop and deploy a fix. Critical issues are prioritized for immediate patching.

4

Disclosure & Credit

After resolution, we notify you. With permission, we publicly credit responsible researchers.

🔐 Safe Harbor & Legal Disclaimer

Aevum News appreciates your efforts to responsibly disclose vulnerabilities. We pledge not to pursue legal action against researchers who comply with this policy.

By submitting a report, you agree to:

  • Not exploit vulnerabilities beyond the minimum required for proof-of-concept
  • Not access, modify, or delete any reader data, financial records, or proprietary systems
  • Not use automated tools in a way that generates excessive traffic or impacts service availability
  • Keep findings confidential until a patch is deployed and the public disclosure window has passed
  • Submit reports solely through this official channel

For urgent, critical-severity issues (active exploitation, ransomware, or imminent data breach), contact: security@aevumnews.com

Frequently Asked Questions

Common questions about our vulnerability disclosure program.

Will I be credited for my finding?
Yes. Unless you request anonymity, we will acknowledge your contribution in our public security acknowledgments page and monthly security updates.
Do you offer bug bounty rewards?
Aevum News currently operates a recognition-based disclosure program. We are evaluating a monetary bounty structure for critical infrastructure vulnerabilities in Q4 2025.
What happens if I report in good faith but it's not a vulnerability?
We appreciate all responsible reports. If a submission falls outside scope or isn't exploitable, we will notify you and provide technical feedback if requested.
How long until public disclosure?
We aim for a 90-day disclosure window from initial report receipt, unless coordinated with the reporter for extensions due to complex remediation.