Security & Trust

Vulnerability Disclosure Policy

Aevum News values responsible disclosure and welcomes reports from security researchers and our community to help keep our platforms secure.

Last Updated: November 12, 2025 Version: 2.4 Managed by: Trust & Safety Team

1. Our Commitment

Aevum News operates a globally distributed digital publishing platform that handles sensitive reader data, editorial workflows, and real-time news distribution. We take information security seriously and acknowledge that independent security research plays a critical role in safeguarding our ecosystem.

This policy outlines how to responsibly report security vulnerabilities, what falls within scope, and the protections we provide to researchers who act in good faith.

2. Scope

Please restrict your testing to the following in-scope assets. Out-of-scope systems should not be tested under this policy.

In Scope

  • www.aevumnews.com & all subdomains
  • Mobile applications (iOS & Android)
  • API endpoints documented in our developer portal
  • Reader authentication & account management flows
  • Newsletter distribution infrastructure

Out of Scope

  • Third-party services & CDNs (Cloudflare, AWS, Stripe, etc.)
  • Social media accounts & email marketing platforms
  • Physical security & social engineering attacks
  • Denial of Service (DoS/DDoS) campaigns
  • Automated scanning at scale without prior coordination

3. How to Report

Submit all vulnerability reports through our dedicated security channel. For sensitive findings, please encrypt your initial message using the PGP key provided below.

📧
Security Email
security@aevumnews.com
🔐
Encryption Recommended
PGP / GPG for sensitive payloads
Do not include live exploit code in unencrypted emails

4. What to Include

To help us triage and resolve issues efficiently, please include the following in your report:

5. Safe Harbor & Legal Protections

We respect and protect the rights of security researchers who follow this policy. Aevum News will not pursue legal or administrative action against researchers who:

If your research touches on out-of-scope systems or inadvertently triggers security controls, contact us immediately at security@aevumnews.com. We are committed to working collaboratively, not punitively.

6. Response & Disclosure Process

Acknowledgment (24–48 hours)
We will confirm receipt of your report and assign a case identifier.
Triage & Validation (3–5 business days)
Our security engineering team will verify the finding, assess severity, and classify the issue.
Remediation (Varies by severity)
Critical/High: 7–14 days | Medium: 14–30 days | Low: Next scheduled release cycle
Verification & Closure
We will deploy fixes, validate the patch, and notify you once the vulnerability is resolved.
Public Disclosure (Post-Resolution)
With your consent, we may credit you in our security transparency reports. Anonymous attribution is always available.

7. PGP Public Key

For researchers wishing to encrypt reports containing sensitive payloads or detailed exploit logic, use the following public key:

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBF6Kz3QBEAC8vN5Z3qY8jF4mK2xP9RnLwV7tQ8sH1bY3cD4eF5gH6iJ7kL8
mN9oP0qR1sT2uV3wX4yZ5aB6cD7eF8gH9iJ0kL1mN2oP3qR4sT5uV6wX7yZ8aB9
cD0eF1gH2iJ3kL4mN5oP6qR7sT8uV9wX0yZ1aB2cD3eF4gH5iJ6kL7mN8oP9qR0
sT1uV2wX3yZ4aB5cD6eF7gH8iJ9kL0mN1oP2qR3sT4uV5wX6yZ7aB8cD9eF0gH1
iJ2kL3mN4oP5qR6sT7uV8wX9yZ0aB1cD2eF3gH4iJ5kL6mN7oP8qR9sT0uV1wX2
yZ3aB4cD5eF6gH7iJ8kL9mN0oP1qR2sT3uV4wX5yZ6aB7cD8eF9gH0iJ1kL2mN3
oP4qR5sT6uV7wX8yZ9aB0cD1eF2gH3iJ4kL5mN6oP7qR8sT9uV0wX1yZ2aB3cD4
eF5gH6iJ7kL8mN9oP0qR1sT2uV3wX4yZ5aB6cD7eF8gH9iJ0kL1mN2oP3qR4sT5
uV6wX7yZ8aB9cD0eF1gH2iJ3kL4mN5oP6qR7sT8uV9wX0yZ1aB2cD3eF4gH5iJ6
kL7mN8oP9qR0sT1uV2wX3yZ4aB5cD6eF7gH8iJ9kL0mN1oP2qR3sT4uV5wX6yZ7
aB8cD9eF0gH1iJ2kL3mN4oP5qR6sT7uV8wX9yZ0aB1cD2eF3gH4iJ5kL6mN7oP8
qR9sT0uV1wX2yZ3aB4cD5eF6gH7iJ8kL9mN0oP1qR2sT3uV4wX5yZ6aB7cD8eF9
=xA9v
-----END PGP PUBLIC KEY BLOCK-----

Key fingerprint: 8A3F 2B9C D1E5 4F7A 6C0D 9E2B 3A5F 8C1D 7E4B 9A0C

8. Changes to This Policy

Aevum News may update this Vulnerability Disclosure Policy to reflect changes in our infrastructure, industry standards, or legal requirements. Updates will be documented with a new version number and publication date. Researchers are encouraged to review this page before submitting reports.