BUG BOUNTY PROGRAM ACTIVE

Report a Vulnerability

We value the security community's role in protecting Aevum Zenth's global infrastructure. Submit findings securely and responsibly.

Submit Report PGP Key
24h Avg. Response
$50K+ Max Bounty
1,247 Reports Fixed
892 Researchers

PGP Encryption Key

security@ae-vumzenth.sec
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBF3YZ5sBEAC1J7kX8vG7hQ5rT3xZ8vK9mL2nP5wR6tE7yU9iO3aS1dF4gH6 jK8lM0nQ2pS4rU6tW8vY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW4xY6zA8 bC0dE2fG4hI6jK8lM0nO2pQ4rS6tU8vW0xY2zA4bC6dE8fG0hI2jK4lM6nO8pQ0 rS2tU4vW6xY8zA0bC2dE4fG6hI8jK0lM2nO4pQ6rS8tU0vW2xY4zA6bC8dE0fG2 hI4jK6lM8nO0pQ2rS4tU6vW8xY0zA2bC4dE6fG8hI0jK2lM4nO6pQ8rS0tU2vW4 xY6zA8bC0dE2fG4hI6jK8lM0nO2pQ4rS6tU8vW0xY2zA4bC6dE8fG0hI2jK4lM6 nO8pQ0rS2tU4vW6xY8zA0bC2dE4fG6hI8jK0lM2nO4pQ6rS8tU0vW2xY4zA6bC8 EQARAQAB =Z9X2 -----END PGP PUBLIC KEY BLOCK-----

Encrypt your submission with this key before sending to security@ae-vumzenth.sec

Reward Tiers

Critical
Up to $50,000

RCE, SQLi, authentication bypass in production systems handling sensitive data or critical infrastructure.

High
Up to $15,000

XSS, SSRF, IDOR, privilege escalation, or vulnerabilities in non-critical production systems.

Medium
Up to $5,000

Open redirects, information disclosure, CSRF, or security misconfigurations with limited impact.

Low
$100 - $1,000

Minor security issues, UI security flaws, or theoretical vulnerabilities with no practical exploit path.

Submit a Report

We'll use this to coordinate with you. Consider using PGP for sensitive details.

Safe Harbor & Policy

Aevum Zenth is committed to protecting researchers who report vulnerabilities in good faith. Our safe harbor policy includes:

  • Immunity from legal action for authorized security testing conducted responsibly
  • No cease-and-desist letters or takedown notices for good faith disclosures
  • Confidential handling of all submissions and researcher identities
  • Clear communication timelines: acknowledgment within 24 hours, resolution updates weekly
  • Exclusion of DoS attacks, social engineering, and physical security testing from scope
  • Requirement to immediately cease testing if systems appear to be in a compromised state

Frequently Asked Questions

What assets are in scope?

All web applications, APIs, mobile applications, and cloud infrastructure domains registered to *.ae-vumzenth.sec and *.zenth.global are in scope. This includes production, staging, and development environments.

When are bounties paid?

Bounties are paid within 15 business days after the vulnerability is confirmed and acknowledged by our security team. Payments are processed via bank transfer, cryptocurrency, or gift cards based on your preference.

What constitutes responsible disclosure?

Responsible disclosure means reporting vulnerabilities privately to our security team, allowing reasonable time for remediation before public disclosure, and avoiding data exfiltration, system disruption, or privacy violations during testing.

Do you require PGP encryption?

While not mandatory, we strongly encourage PGP encryption for all submissions containing sensitive information. If you submit without encryption, our team will still handle your report with strict confidentiality protocols.