Vulnerability Disclosure Policy
Aevum Zenth Conglomerate is committed to protecting the privacy and security of our data and systems across all 400+ subsidiaries. We encourage responsible disclosure of vulnerabilities that may impact our infrastructure, applications, or user data.
Report a Vulnerability
If you believe you have discovered a security vulnerability in any Aevum Zenth property, please report it to us immediately using the following secure contact details.
security@aezumzenth.com1. Scope
The following assets are in scope for this policy:
- All Aevum Zenth owned and operated domains (aezumzenth.com and subsidiaries).
- Public-facing web applications, APIs, and mobile applications.
- Infrastructure components directly accessible from the public internet.
- Third-party integrations specifically listed on our security partners page.
The following are explicitly out of scope. Please do not report vulnerabilities for these:
- Distributed Denial of Service (DoS) attacks.
- Social engineering, phishing, or physical security.
- Vulnerabilities in third-party applications or services not owned by Aevum Zenth.
- Issues related to browser-specific rendering or extensions.
- Self-XSS (Cross-Site Scripting that affects only the user performing the action).
2. Safe Harbor
Aevum Zenth values the security community. As long as you act in good faith, you will not be subject to legal action or be otherwise penalized for actions that may violate applicable law. We will not pursue legal action against researchers who follow this policy, and we will consider the research covered by safe harbor.
Activities are considered within safe harbor if:
- You do not exfiltrate, modify, or delete data.
- You do not impact production availability or integrity.
- You report the vulnerability to us before disclosing it publicly.
- You provide a reasonable time for us to resolve the issue before public disclosure.
3. Disclosure Process
Submission
When reporting a vulnerability, please include:
- Description of the vulnerability.
- Steps to reproduce the issue.
- Proof of concept (PoC) code or screenshots if applicable.
- Your name/handle for attribution (optional).
Encryption
For sensitive reports, please encrypt your email using our PGP key below.
Response Timeline
- Acknowledgment: Within 24 hours of submission.
- Analysis: Within 3 business days.
- Resolution: Within 90 days, or sooner for critical vulnerabilities.
- Disclosure: We may disclose the vulnerability within 90 days if a fix has not been identified and the risk is deemed acceptable.
4. Contact
For any questions regarding this policy or the security of Aevum Zenth systems, please contact our Security Operations Center (SOC).
Email: security@aezumzenth.com
Emergency: +1 (800) 555-0199 (Critical production impacts only)