Vulnerability Disclosure Policy
Aevum News values responsible disclosure and welcomes reports from security researchers and our community to help keep our platforms secure.
1. Our Commitment
Aevum News operates a globally distributed digital publishing platform that handles sensitive reader data, editorial workflows, and real-time news distribution. We take information security seriously and acknowledge that independent security research plays a critical role in safeguarding our ecosystem.
This policy outlines how to responsibly report security vulnerabilities, what falls within scope, and the protections we provide to researchers who act in good faith.
2. Scope
Please restrict your testing to the following in-scope assets. Out-of-scope systems should not be tested under this policy.
In Scope
- www.aevumnews.com & all subdomains
- Mobile applications (iOS & Android)
- API endpoints documented in our developer portal
- Reader authentication & account management flows
- Newsletter distribution infrastructure
Out of Scope
- Third-party services & CDNs (Cloudflare, AWS, Stripe, etc.)
- Social media accounts & email marketing platforms
- Physical security & social engineering attacks
- Denial of Service (DoS/DDoS) campaigns
- Automated scanning at scale without prior coordination
3. How to Report
Submit all vulnerability reports through our dedicated security channel. For sensitive findings, please encrypt your initial message using the PGP key provided below.
4. What to Include
To help us triage and resolve issues efficiently, please include the following in your report:
- Clear Description: A concise summary of the vulnerability and its potential impact
- Reproduction Steps: Detailed, step-by-step instructions to safely replicate the issue
- Affected Assets: URLs, API endpoints, or app versions involved
- Proof of Concept: Screenshots, logs, or minimal safe code snippets (no destructive payloads)
- Severity Assessment: Your estimated impact (Low, Medium, High, Critical) using CVSS v3.1 or similar
5. Safe Harbor & Legal Protections
We respect and protect the rights of security researchers who follow this policy. Aevum News will not pursue legal or administrative action against researchers who:
- Act in good faith and avoid malicious intent
- Refrain from accessing, modifying, or deleting user/editorial data
- Do not disrupt production services or launch automated attacks
- Keep discovered vulnerabilities confidential until resolved
- Provide a reasonable window for patching before public disclosure
If your research touches on out-of-scope systems or inadvertently triggers security controls, contact us immediately at security@aevumnews.com. We are committed to working collaboratively, not punitively.
6. Response & Disclosure Process
7. PGP Public Key
For researchers wishing to encrypt reports containing sensitive payloads or detailed exploit logic, use the following public key:
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBF6Kz3QBEAC8vN5Z3qY8jF4mK2xP9RnLwV7tQ8sH1bY3cD4eF5gH6iJ7kL8
mN9oP0qR1sT2uV3wX4yZ5aB6cD7eF8gH9iJ0kL1mN2oP3qR4sT5uV6wX7yZ8aB9
cD0eF1gH2iJ3kL4mN5oP6qR7sT8uV9wX0yZ1aB2cD3eF4gH5iJ6kL7mN8oP9qR0
sT1uV2wX3yZ4aB5cD6eF7gH8iJ9kL0mN1oP2qR3sT4uV5wX6yZ7aB8cD9eF0gH1
iJ2kL3mN4oP5qR6sT7uV8wX9yZ0aB1cD2eF3gH4iJ5kL6mN7oP8qR9sT0uV1wX2
yZ3aB4cD5eF6gH7iJ8kL9mN0oP1qR2sT3uV4wX5yZ6aB7cD8eF9gH0iJ1kL2mN3
oP4qR5sT6uV7wX8yZ9aB0cD1eF2gH3iJ4kL5mN6oP7qR8sT9uV0wX1yZ2aB3cD4
eF5gH6iJ7kL8mN9oP0qR1sT2uV3wX4yZ5aB6cD7eF8gH9iJ0kL1mN2oP3qR4sT5
uV6wX7yZ8aB9cD0eF1gH2iJ3kL4mN5oP6qR7sT8uV9wX0yZ1aB2cD3eF4gH5iJ6
kL7mN8oP9qR0sT1uV2wX3yZ4aB5cD6eF7gH8iJ9kL0mN1oP2qR3sT4uV5wX6yZ7
aB8cD9eF0gH1iJ2kL3mN4oP5qR6sT7uV8wX9yZ0aB1cD2eF3gH4iJ5kL6mN7oP8
qR9sT0uV1wX2yZ3aB4cD5eF6gH7iJ8kL9mN0oP1qR2sT3uV4wX5yZ6aB7cD8eF9
=xA9v
-----END PGP PUBLIC KEY BLOCK-----
Key fingerprint: 8A3F 2B9C D1E5 4F7A 6C0D 9E2B 3A5F 8C1D 7E4B 9A0C
8. Changes to This Policy
Aevum News may update this Vulnerability Disclosure Policy to reflect changes in our infrastructure, industry standards, or legal requirements. Updates will be documented with a new version number and publication date. Researchers are encouraged to review this page before submitting reports.