How to Submit a Report

Follow these steps to submit a vulnerability report. All submissions are handled by our internal Security Operations Center (SOC) and are treated with strict confidentiality.


  • Use the form below to describe the vulnerability in detail, including reproduction steps and impact assessment.
  • If the report contains sensitive data, encrypt your submission using our PGP key provided further down this page.
  • You will receive an automated acknowledgment within 2 hours, followed by a dedicated security engineer assignment.
  • Do not publish or disclose the vulnerability until it has been fully resolved and publicly announced by Aevum Zenth.

Program Scope

In Scope

  • All aevumzenth.com and zenthcorp.com subdomains
  • Mobile applications (iOS & Android) published by Aevum Zenth
  • Customer-facing APIs and REST endpoints
  • Cloud infrastructure (AWS, Azure, GCP resources under Aevum Zenth)
  • Third-party integrations and OAuth flows
  • Internal tools and dashboards accessible externally
  • Hardware devices manufactured or sold by Aevum Zenth subsidiaries

Out of Scope

  • Social engineering attacks (phishing, vishing, pretexting)
  • DDoS or denial-of-service attacks against any Aevum Zenth service
  • Vulnerabilities in third-party services not directly operated by Aevum Zenth
  • Issues related to SEO, spam, or clickjacking without further impact
  • Self-XSS or browser-side issues with no server-side impact
  • Physical security of Aevum Zenth facilities

What We Accept

  • Remote Code Execution (RCE) and Server-Side Request Forgery (SSRF)
  • SQL Injection (SQLi), NoSQL Injection, and Command Injection
  • Cross-Site Scripting (XSS) with sensitive data access or session hijacking
  • Authentication bypass, privilege escalation, and broken access control
  • Server-side template injection and deserialization vulnerabilities
  • Data exposure via misconfigured storage, APIs, or logging
  • Insecure direct object references (IDOR) and mass assignment
  • Cryptographic failures and hardcoded credentials
  • Supply chain and dependency vulnerabilities affecting Aevum Zenth services

Response Timeline

Submission Received 0h

Automated acknowledgment email sent to your provided address. Your report is logged and triaged by our SOC.

Initial Triage 2h

A dedicated security engineer reviews your report, confirms the submission, and begins investigation.

Confirmation or Rejection 24h

We respond with a validation of the vulnerability, severity classification, and estimated fix timeline.

Remediation In Progress 7 days

Engineering teams work on the fix. You will receive periodic status updates.

Resolution & Reward 14 days

After verification, the vulnerability is closed and your reward (if applicable) is processed.

Reward Structure

Severity Description Base Reward
Critical RCE, complete system compromise, database full breach $25,000 – $100,000
High Sensitive data exposure, auth bypass, privilege escalation $7,500 – $25,000
Medium XSS with impact, IDOR, SSRF with internal network access $2,000 – $7,500
Low Minor security misconfigurations, informational findings $250 – $2,000

* Final reward amounts are determined by the impact and quality of the report. Multiple related vulnerabilities may be combined into a single report for a higher reward. Non-monetary recognition is also provided via our Hall of Fame.

PGP Public Key

Encrypt your report using the key below before submitting, especially if it contains sensitive data or proof-of-concept material.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBF7Qp4wBEADj2V4H5b9xM8K7n3ZqX0fH2YpR9Vw3mDcT5Kx8L6Q4a0Jf9R7
Z1hN2Y5x3K8pVw6t4mR9dQ0cF3sL8aJ5gE2vX7bT4uK0pN6wY1rQ8dM3fH2cA5jI
9eO0xR4tL6kV1nW7bS8pD3yG5mQ2fE0jC9hX6uA4vT1rK3oN8yW7sP2dM5eR0bF4
cL9aI3gJ6kT1xV8wN2oE5rY7uQ4pD0sM3fH9cA6jI2eO5xR8tL1kV4nW0bS7pD3y
G5mQ9fE2jC8hX1uA6vT3rK5oN0yW4sP7dM1eR9bF2cL6aI0gJ3kT8xV1wN5oE2rY
0uQ7pD3sM6fH4cA9jI1eO8xR2tL5kV7nW3bS0pD6yG1mQ4fE9jC2hX5uA0vT7rK8
oN3yW1sP4dM5eR2bF7cL0aI3gJ6kT1xV8wN2oE5rY7uQ4pD0sM3fH9cA6jI2eO5x
R8tL1kV4nW0bS7pD3yG5mQ9fE2jC8hX1uA6vT3rK5oN0yW4sP7dM1eR9bF2cL6aI
0gJ3kT8xV1wN5oE2rY0uQ7pD3sM6fH4cA9jI1eO8xR2tL5kV7nW3bS0pD6yG1mQ4
fE9jC2hX5uA0vT7rK8oN3yW1sP4dM5eR2bF7cL0aI3gJ6kT1xV8wN2oE5rY7uQ4p
D0sM3fH9cA6jI2eO5xR8tL1kV4nW0bS7pD3yG5mQ9fE2jC8hX1uA6vT3rK5oN0y
=WkRz
-----END PGP PUBLIC KEY BLOCK-----

Submit a Vulnerability Report

The URL or endpoint where the vulnerability was found.

The more detail you provide, the faster we can triage and resolve the issue.

Safe Harbor Policy

Aevum Zenth Conglomerate will not threaten or take legal action against researchers who: (1) promptly report any vulnerabilities or security issues, (2) make a good faith effort to avoid privacy violations, service disruptions, and data destruction, (3) only access attributes or data absolutely necessary to demonstrate the vulnerability, and (4) immediately notify Aevum Zenth upon discovering a vulnerability.


By submitting a report, you agree to engage in good-faith responsible disclosure and not exploit or disclose the vulnerability publicly before Aevum Zenth has had a reasonable time to remediate the issue.

Frequently Asked Questions

How long does it take to receive a response?

You will receive an automated acknowledgment within 2 hours of submission. Our security team aims to provide a substantive response — confirming, requesting more information, or declining — within 24 hours. Critical and high-severity reports are prioritized for same-day review.

What happens after I submit a report?

Your report is triaged by our SOC, assigned to a security engineer, and investigated. You will receive status updates throughout the process. Once the fix is deployed and verified, you will be notified and any applicable reward will be processed.

Can I remain anonymous?

Yes. You can use a pseudonym and a secure communication channel. Rewards for anonymous submissions can be paid via cryptocurrency or gift cards. We will never disclose your identity without your explicit written consent.

How are rewards paid?

Rewards are typically paid via wire transfer, PayPal, or cryptocurrency (BTC, ETH, USDC). For researchers in restricted jurisdictions, we offer alternative compensation including gift cards or merchandise. Rewards are processed within 10 business days of resolution.

What if my report is rejected?

We provide detailed reasoning for every rejected report. If you disagree with the assessment, you can request a review from our security leadership team. Duplicate reports from other researchers will still be acknowledged, and we encourage collaborative reporting.

Do you have a Hall of Fame?

Yes. Researchers who submit valid and impactful vulnerability reports are eligible to be featured in our Hall of Fame (with permission). Past contributors are also invited to exclusive security summits and early access to new vulnerability disclosure program features.

Direct Contact

Need to Reach Us Directly?

For urgent security concerns, encrypted communications, or questions about this program.