Vulnerability Disclosure & Bug Bounty

We welcome responsible security researchers to help identify and remediate vulnerabilities across the Aevum Encyclopedia platform. All reports are handled with strict confidentiality and legal protection.

Verified Responsible Disclosure Program • Safe Harbor Active

Program Scope

We accept reports for vulnerabilities affecting the following in-scope assets. Any systems not explicitly listed are considered out of scope.

In Scope

  • *.aevum.com
  • app.aevum.com / api.aevum.com
  • search.aevum.com
  • cdn.aevumenc.org
  • Aevum mobile applications (iOS/Android)
  • OAuth & SSO authentication flows

Out of Scope

  • Third-party services & CDN providers
  • Social engineering, phishing, or physical attacks
  • Denial of Service (DoS/DDoS) or automated load testing
  • Issues with publicly archived or deprecated endpoints
  • Low-risk UI/UX inconsistencies without security impact

Vulnerability Classes & Rewards

Rewards are determined by CVSS 3.1 scoring, exploitability, business impact, and responsible disclosure adherence. Payments are processed within 30 days of resolution.

Severity CVSS Range Examples Reward
Critical 9.0 – 10.0 Remote code execution, full system compromise, admin privilege escalation $7,500 – $15,000
High 7.0 – 8.9 Authentication bypass, SQLi, stored XSS, sensitive data exposure $3,000 – $7,499
Medium 4.0 – 6.9 Reflected XSS, IDOR, CSRF without impact, weak session management $1,000 – $2,999
Low 0.1 – 3.9 Open redirects, minor info leaks, rate-limiting bypass $250 – $999
Informational N/A Security misconfigurations, best practice recommendations Recognition & Swag

How to Report

Submit all vulnerability reports through our secure channel. Please include proof-of-concept code, steps to reproduce, and affected endpoints.

Secure Submission Channel

Submission Email security@aevum.com
PGP Public Key Fingerprint: 8A3C 9F2E 7D1B 4E5A 6C8F
Response SLA Acknowledgment: 48h | Updates: 14d
Preferred Format PDF or encrypted text archive

Rules of Engagement

To maintain platform integrity and legal compliance, all participants must adhere to the following guidelines:

Legal & Compliance Disclaimer