Program Scope
We accept reports for vulnerabilities affecting the following in-scope assets. Any systems not explicitly listed are considered out of scope.
In Scope
- *.aevum.com
- app.aevum.com / api.aevum.com
- search.aevum.com
- cdn.aevumenc.org
- Aevum mobile applications (iOS/Android)
- OAuth & SSO authentication flows
Out of Scope
- Third-party services & CDN providers
- Social engineering, phishing, or physical attacks
- Denial of Service (DoS/DDoS) or automated load testing
- Issues with publicly archived or deprecated endpoints
- Low-risk UI/UX inconsistencies without security impact
Vulnerability Classes & Rewards
Rewards are determined by CVSS 3.1 scoring, exploitability, business impact, and responsible disclosure adherence. Payments are processed within 30 days of resolution.
| Severity | CVSS Range | Examples | Reward |
|---|---|---|---|
| Critical | 9.0 – 10.0 | Remote code execution, full system compromise, admin privilege escalation | $7,500 – $15,000 |
| High | 7.0 – 8.9 | Authentication bypass, SQLi, stored XSS, sensitive data exposure | $3,000 – $7,499 |
| Medium | 4.0 – 6.9 | Reflected XSS, IDOR, CSRF without impact, weak session management | $1,000 – $2,999 |
| Low | 0.1 – 3.9 | Open redirects, minor info leaks, rate-limiting bypass | $250 – $999 |
| Informational | N/A | Security misconfigurations, best practice recommendations | Recognition & Swag |
How to Report
Submit all vulnerability reports through our secure channel. Please include proof-of-concept code, steps to reproduce, and affected endpoints.
Secure Submission Channel
Rules of Engagement
To maintain platform integrity and legal compliance, all participants must adhere to the following guidelines:
- No Data Access or Modification: Do not read, modify, or delete user data. Only access endpoints relevant to your proof-of-concept.
- No Automated Scanning: Large-scale or aggressive automated scanning is prohibited without prior written consent.
- Safe Harbor: Activities conducted in good faith within scope will not result in legal action, account suspension, or retaliation.
- Embargo Period: Do not disclose findings publicly until 90 days after patch deployment or mutual agreement.
- Chain of Custody: Retain all evidence and provide complete reproduction steps. Partial or theoretical reports may not qualify for rewards.
Legal & Compliance Disclaimer
1. This program does not waive any rights or defenses available to Aevum Encyclopedia under applicable law.
2. Unauthorized access to systems outside the defined scope may violate the Computer Fraud and Abuse Act (CFAA) and international equivalents.
3. Reward eligibility requires full disclosure of discovery methodology and no prior public reporting.
4. Aevum reserves the right to modify, suspend, or terminate this program at any time with notice.
Program Version: 2.4.1 • Last Updated: November 12, 2025 • Governing Law: State of Delaware, USA