Public Security Disclosures

Security, Transparency & Trust

Aevum Zenth maintains rigorous security standards across all 400 subsidiaries. We are committed to responsible disclosure, rapid incident response, and full regulatory compliance.

🛡️ Vulnerability Disclosure Policy (VDP)

We welcome security researchers to help us identify and remediate vulnerabilities. Our VDP applies to all Aevum Zenth domains, applications, APIs, IoT endpoints, and physical security systems operating under our brand.

✅ In Scope

  • All *.aevumzenth.com & *.zenth.global domains
  • Public-facing APIs, SDKs, & mobile applications
  • Cloud infrastructure & container orchestration layers
  • Hardware endpoints & IoT telemetry channels
  • Authentication, authorization & session management

🚫 Out of Scope

  • Denial of Service (DoS) or DDoS attacks
  • Social engineering, phishing, or physical intrusion
  • Automated scanning without prior written authorization
  • Vulnerabilities in third-party services outside our control
  • Cosmetic UI issues or non-security functionality bugs

⚖️ Safe Harbor & Legal Protection

Researchers acting in good faith and following our disclosure guidelines will not face legal action. We grant explicit permission for non-disruptive testing within scope. Do not access, modify, or delete user data, and cease testing immediately upon reaching a production environment boundary.

⏱️ Response SLA & Triage Workflow

Our Security Operations Center (SOC) operates 24/7/365. Vulnerability reports are triaged, validated, and routed to the appropriate engineering division.

24h
Acknowledgment
72h
Initial Assessment
14d
Mitigation Target
1

Receipt & Acknowledgment

Report logged, assigned a tracking ID, and confirmed within 24 hours. PGP-encrypted channels preferred.

2

Validation & Triage

SOC engineers verify proof-of-concept, determine severity (CVSS v3.1), and route to the affected division.

3

Remediation & Patching

Engineering implements fixes, conducts regression testing, and deploys across production/staging environments.

4

Verification & Closure

Researcher verifies fix, public disclosure coordinated, and bounty/acknowledgment issued per severity tier.

📜 Compliance & Certifications

Aevum Zenth maintains continuous compliance across multiple regulatory frameworks to protect data, infrastructure, and customer trust.

🔒 Data & Privacy

GDPR, CCPA, HIPAA (Health Sciences division), and SOC 2 Type II certified. Automated DLP pipelines and zero-trust data access controls enforce least-privilege principles.

🏗️ Infrastructure & Operations

ISO 27001, ISO 22301 (Business Continuity), NIST CSF, and FedRAMP Moderate (Aerospace & Gov contracts). Annual third-party penetration tests and red-team exercises.

🔍 Audit Transparency

Compliance audit reports, penetration test summaries (redacted), and security architecture diagrams are available to enterprise clients under NDA. Request via our compliance portal.

📩 How to Report

Submit vulnerability reports, security inquiries, or compliance requests through our dedicated encrypted channels.

🔐

Encrypted Email

security@aevumzenth.com

PGP encrypted submissions preferred

🌐

Web Portal

bounty.zenth.global

Bug bounty & disclosure dashboard

Public PGP Key (Fingerprint: A8F2 9C41 D7B3 0E12 4A5F 8C90 2D11 7E34 B9A6 00Z2)

-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBF2...
wF... [TRUNCATED FOR DISPLAY] ...9K
-----END PGP PUBLIC KEY BLOCK-----
}