How to Report a Vulnerability
Please send a detailed report to our dedicated security team. Encrypted submissions are strongly recommended.
Primary Contact
security@aevumnews.com
PGP Public Key: Download Key (SHA256: 8F3A 2B91 C4D7 ...)
- Clear description of the vulnerability and steps to reproduce
- Impact assessment and affected endpoints/assets
- PoC code or screenshots (if applicable)
- Your contact information and preferred disclosure method
Program Scope
We welcome reports for vulnerabilities affecting the following assets. Out-of-scope items will be acknowledged but may not qualify for recognition or rewards.
🟢 In Scope
- aevumnews.com (Web Application)
- api.aevumnews.com (Public APIs)
- accounts.aevumnews.com (Authentication)
- Mobile Apps (iOS & Android)
- CDN Edge Configurations
- Customer-facing Infrastructure
🔴 Out of Scope
- Denial of Service (DoS/DDoS)
- Business Logic Disputes
- Social Engineering / Phishing
- Third-party Services
- Missing Bug Bounty Headers
- Automated Scan Results
Severity Classification & Response
We use the CVSS v3.1 scoring system to triage and prioritize submissions. Estimated response times are provided below.
| Severity | CVSS Range | Response Time | Resolution Target |
|---|---|---|---|
| Critical | 9.0 – 10.0 | Within 2 hours | 24 – 48 hours |
| High | 7.0 – 8.9 | Within 12 hours | 3 – 7 days |
| Medium | 4.0 – 6.9 | Within 3 days | 14 – 30 days |
| Low | 0.1 – 3.9 | Within 5 days | Next release cycle |
Our Disclosure Process
1. Submission
You submit a detailed report via secure email. We encourage PGP encryption for sensitive details.
2. Acknowledgment
You'll receive a confirmation within the timeframe matching the reported severity. A ticket is created internally.
3. Triage & Validation
Our security engineers reproduce and validate the issue. We may request additional information or PoC details.
4. Remediation
The responsible engineering team develops and tests a fix. We keep you updated on progress and deployment status.
5. Resolution & Credit
Once patched, we notify you. You may request public recognition in our security hall of fame or prefer anonymity.
Safe Harbor & Legal Assurance
Aevum News will not pursue civil or criminal action, or file or support the filing of a complaint with any law enforcement or government agency, against anyone who follows this policy. We consider research conducted under this policy to be \"authorized\" activity and will not seek to restrict publication of information about a security vulnerability following disclosure.
By submitting a report, you agree to:
- Not interact with accounts of other users without their explicit permission
- Not download, modify, or delete data belonging to Aevum News or its users
- Not test with production systems beyond what is necessary to prove the vulnerability
- Keep discovered vulnerabilities confidential until patched and publicly disclosed
Frequently Asked Questions
Do you offer bug bounty rewards?
We currently offer recognition in our annual Security Hall of Fame and priority access to platform features. Monetary rewards are evaluated case-by-case for critical infrastructure findings.
Can I report vulnerabilities in third-party services?
No. We only accept reports for assets under our direct control. Please refer to the vendor's own disclosure program for third-party services.
What happens after I submit a report?
You will receive an automated acknowledgment, followed by a personal response from our security team within the severity-based timeframe. We maintain transparent communication throughout the triage and remediation process.