We welcome responsible disclosure. Help us keep Aevum Zenth's 400+ subsidiaries, digital systems, and global infrastructure secure.
Follow these steps to submit a vulnerability report. All submissions are handled by our internal Security Operations Center (SOC) and are treated with strict confidentiality.
Automated acknowledgment email sent to your provided address. Your report is logged and triaged by our SOC.
A dedicated security engineer reviews your report, confirms the submission, and begins investigation.
We respond with a validation of the vulnerability, severity classification, and estimated fix timeline.
Engineering teams work on the fix. You will receive periodic status updates.
After verification, the vulnerability is closed and your reward (if applicable) is processed.
| Severity | Description | Base Reward |
|---|---|---|
| Critical | RCE, complete system compromise, database full breach | $25,000 – $100,000 |
| High | Sensitive data exposure, auth bypass, privilege escalation | $7,500 – $25,000 |
| Medium | XSS with impact, IDOR, SSRF with internal network access | $2,000 – $7,500 |
| Low | Minor security misconfigurations, informational findings | $250 – $2,000 |
* Final reward amounts are determined by the impact and quality of the report. Multiple related vulnerabilities may be combined into a single report for a higher reward. Non-monetary recognition is also provided via our Hall of Fame.
Encrypt your report using the key below before submitting, especially if it contains sensitive data or proof-of-concept material.
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBF7Qp4wBEADj2V4H5b9xM8K7n3ZqX0fH2YpR9Vw3mDcT5Kx8L6Q4a0Jf9R7 Z1hN2Y5x3K8pVw6t4mR9dQ0cF3sL8aJ5gE2vX7bT4uK0pN6wY1rQ8dM3fH2cA5jI 9eO0xR4tL6kV1nW7bS8pD3yG5mQ2fE0jC9hX6uA4vT1rK3oN8yW7sP2dM5eR0bF4 cL9aI3gJ6kT1xV8wN2oE5rY7uQ4pD0sM3fH9cA6jI2eO5xR8tL1kV4nW0bS7pD3y G5mQ9fE2jC8hX1uA6vT3rK5oN0yW4sP7dM1eR9bF2cL6aI0gJ3kT8xV1wN5oE2rY 0uQ7pD3sM6fH4cA9jI1eO8xR2tL5kV7nW3bS0pD6yG1mQ4fE9jC2hX5uA0vT7rK8 oN3yW1sP4dM5eR2bF7cL0aI3gJ6kT1xV8wN2oE5rY7uQ4pD0sM3fH9cA6jI2eO5x R8tL1kV4nW0bS7pD3yG5mQ9fE2jC8hX1uA6vT3rK5oN0yW4sP7dM1eR9bF2cL6aI 0gJ3kT8xV1wN5oE2rY0uQ7pD3sM6fH4cA9jI1eO8xR2tL5kV7nW3bS0pD6yG1mQ4 fE9jC2hX5uA0vT7rK8oN3yW1sP4dM5eR2bF7cL0aI3gJ6kT1xV8wN2oE5rY7uQ4p D0sM3fH9cA6jI2eO5xR8tL1kV4nW0bS7pD3yG5mQ9fE2jC8hX1uA6vT3rK5oN0y =WkRz -----END PGP PUBLIC KEY BLOCK-----
Aevum Zenth Conglomerate will not threaten or take legal action against researchers who: (1) promptly report any vulnerabilities or security issues, (2) make a good faith effort to avoid privacy violations, service disruptions, and data destruction, (3) only access attributes or data absolutely necessary to demonstrate the vulnerability, and (4) immediately notify Aevum Zenth upon discovering a vulnerability.
By submitting a report, you agree to engage in good-faith responsible disclosure and not exploit or disclose the vulnerability publicly before Aevum Zenth has had a reasonable time to remediate the issue.
For urgent security concerns, encrypted communications, or questions about this program.