Responsible Vulnerability Disclosure
We actively collaborate with security researchers, developers, and ethical hackers to identify and remediate vulnerabilities across our global infrastructure.
In Scope
π― Covered Systems
- Public-facing web applications & APIs
- Mobile applications (iOS/Android)
- Cloud infrastructure & DNS records
- Subsidiary core services & payment gateways
- Third-party integrations hosted on our domains
Out of Scope
π« Excluded Targets
- Denial of Service (DoS/DDoS) attacks
- Social engineering, phishing, or physical security
- Automated scanning without prior approval
- Third-party services not owned by Aevum Zenth
- CVEs for commercial software or frameworks
Guidelines
π Submission Rules
- Provide clear, step-by-step reproduction instructions
- Do not exfiltrate, modify, or delete user data
- Limit impact to proof-of-concept scope only
- Report vulnerabilities only once (no duplicates)
- Encrypt sensitive attachments using our PGP key
π Submit Report
Report Received Securely
Our security operations team will triage your submission within 24β48 hours. Please retain your reference ID for tracking.
AZ-SEC-000000
Do not share this ID publicly. Expect a confirmation email shortly.