✓ Responsible Disclosure Program

Security & Vulnerability Disclosure

We rely on the security research community to help protect our platforms and readers. If you discover a vulnerability, we appreciate your responsible disclosure.

How to Report a Vulnerability

Please send a detailed report to our dedicated security team. Encrypted submissions are strongly recommended.

Primary Contact

security@aevumnews.com

PGP Public Key: Download Key (SHA256: 8F3A 2B91 C4D7 ...)

Required Information:
  • Clear description of the vulnerability and steps to reproduce
  • Impact assessment and affected endpoints/assets
  • PoC code or screenshots (if applicable)
  • Your contact information and preferred disclosure method

Program Scope

We welcome reports for vulnerabilities affecting the following assets. Out-of-scope items will be acknowledged but may not qualify for recognition or rewards.

🟢 In Scope

  • aevumnews.com (Web Application)
  • api.aevumnews.com (Public APIs)
  • accounts.aevumnews.com (Authentication)
  • Mobile Apps (iOS & Android)
  • CDN Edge Configurations
  • Customer-facing Infrastructure

🔴 Out of Scope

  • Denial of Service (DoS/DDoS)
  • Business Logic Disputes
  • Social Engineering / Phishing
  • Third-party Services
  • Missing Bug Bounty Headers
  • Automated Scan Results

Severity Classification & Response

We use the CVSS v3.1 scoring system to triage and prioritize submissions. Estimated response times are provided below.

Severity CVSS Range Response Time Resolution Target
Critical 9.0 – 10.0 Within 2 hours 24 – 48 hours
High 7.0 – 8.9 Within 12 hours 3 – 7 days
Medium 4.0 – 6.9 Within 3 days 14 – 30 days
Low 0.1 – 3.9 Within 5 days Next release cycle

Our Disclosure Process

1. Submission

You submit a detailed report via secure email. We encourage PGP encryption for sensitive details.

2. Acknowledgment

You'll receive a confirmation within the timeframe matching the reported severity. A ticket is created internally.

3. Triage & Validation

Our security engineers reproduce and validate the issue. We may request additional information or PoC details.

4. Remediation

The responsible engineering team develops and tests a fix. We keep you updated on progress and deployment status.

5. Resolution & Credit

Once patched, we notify you. You may request public recognition in our security hall of fame or prefer anonymity.

Safe Harbor & Legal Assurance

Aevum News will not pursue civil or criminal action, or file or support the filing of a complaint with any law enforcement or government agency, against anyone who follows this policy. We consider research conducted under this policy to be \"authorized\" activity and will not seek to restrict publication of information about a security vulnerability following disclosure.

By submitting a report, you agree to:

  • Not interact with accounts of other users without their explicit permission
  • Not download, modify, or delete data belonging to Aevum News or its users
  • Not test with production systems beyond what is necessary to prove the vulnerability
  • Keep discovered vulnerabilities confidential until patched and publicly disclosed

Frequently Asked Questions

Do you offer bug bounty rewards?

We currently offer recognition in our annual Security Hall of Fame and priority access to platform features. Monetary rewards are evaluated case-by-case for critical infrastructure findings.

Can I report vulnerabilities in third-party services?

No. We only accept reports for assets under our direct control. Please refer to the vendor's own disclosure program for third-party services.

What happens after I submit a report?

You will receive an automated acknowledgment, followed by a personal response from our security team within the severity-based timeframe. We maintain transparent communication throughout the triage and remediation process.