Responsible Disclosure
We value the security research community. If you've discovered a vulnerability in our systems, we welcome your responsible disclosure and collaborate to resolve it swiftly.
\u25B6 Our Commitment to Security
Aevum Zenth Conglomerate operates across 400 subsidiaries and manages critical infrastructure in energy, aerospace, healthcare, finance, and cloud services. We maintain a zero-tolerance policy for unauthorized exploitation, but we actively encourage good-faith security research conducted within the boundaries of this policy.
Our global Security Operations Center (SOC) monitors, triages, and remediates vulnerabilities across all divisions. We believe that transparent collaboration with ethical researchers strengthens our defenses and protects our customers, partners, and employees worldwide.
\u26A1 Scope & Eligibility
We accept reports for vulnerabilities affecting systems explicitly owned and operated by Aevum Zenth or its wholly-owned subsidiaries.
- In Scope: Public-facing web applications, customer portals, APIs, mobile applications, cloud infrastructure (AWS/GCP/Azure tenant resources), authentication systems, and critical internal infrastructure exposed to the internet.
- Out of Scope: Social engineering, physical security, denial-of-service (DoS/DDoS), third-party platforms/services we do not operate, vulnerabilities in public beta/test environments, already reported issues, and automated scanning without prior coordination.
\u270D\uFE0F How to Report
Submit all vulnerability reports to our dedicated security team. For sensitive findings, please encrypt your submission using our PGP key.
PGP Public Key (Fingerprint):
Please include a clear subject line: [SECURITY DISCLOSURE] - Brief Description
\u2705 What to Include
To help us triage and remediate efficiently, please provide:
- Detailed description of the vulnerability and affected systems
- Step-by-step reproduction instructions
- Proof-of-concept code or screenshots (avoid sensitive customer data)
- Your contact information for follow-up
- Preferred communication method and time zone
Do not: Exfiltrate data, modify/delete records, deploy persistent access, impact availability, or test on production systems during peak hours without coordination.
\u23F1\uFE0F Response Process & SLA
Our security team follows a structured incident response workflow:
Critical
Ack: 24h \u2022 Fix: 30-60d
High
Ack: 48h \u2022 Fix: 60-90d
Medium
Ack: 5d \u2022 Fix: 90-180d
Low/Info
Ack: 10d \u2022 Fix: Best effort
We will provide status updates at key milestones: acknowledgment, triage, remediation, patch deployment, and public disclosure coordination. We aim to resolve critical issues before public release.
\u2744\uFE0F Safe Harbor & Legal Protections
If you act in good faith and follow this policy, Aevum Zenth Conglomerate will not pursue civil or criminal action against you for authorized testing of our systems. We consider responsible researchers as allies, not adversaries.
Safe harbor applies when you:
- Do not access, modify, or exfiltrate user data
- Do not disrupt service availability
- Immediately cease testing upon our request
- Report findings exclusively through this policy
This safe harbor does not extend to unauthorized access of third-party systems, physical intrusion, or activities violating applicable laws outside the scope of this policy.
\uD83E\uDD47 Bug Bounty & Recognition
Aevum Zenth operates a structured bug bounty program for eligible vulnerabilities. Rewards are determined by impact, severity, and complexity. Critical findings may qualify for significant financial rewards or research grants.
We offer public recognition in our annual transparency report and security acknowledgments, subject to your preference. Researchers can opt for anonymity, pseudonymity, or full attribution.
Found a vulnerability?
Report it securely through our dedicated channel. We appreciate your efforts to keep our infrastructure and users safe.
\u2709\uFE0F Submit Report Securely