We value the security community's role in protecting Aevum Zenth's global infrastructure. Submit findings securely and responsibly.
Encrypt your submission with this key before sending to security@ae-vumzenth.sec
RCE, SQLi, authentication bypass in production systems handling sensitive data or critical infrastructure.
XSS, SSRF, IDOR, privilege escalation, or vulnerabilities in non-critical production systems.
Open redirects, information disclosure, CSRF, or security misconfigurations with limited impact.
Minor security issues, UI security flaws, or theoretical vulnerabilities with no practical exploit path.
Aevum Zenth is committed to protecting researchers who report vulnerabilities in good faith. Our safe harbor policy includes:
All web applications, APIs, mobile applications, and cloud infrastructure domains registered to *.ae-vumzenth.sec and *.zenth.global are in scope. This includes production, staging, and development environments.
Bounties are paid within 15 business days after the vulnerability is confirmed and acknowledged by our security team. Payments are processed via bank transfer, cryptocurrency, or gift cards based on your preference.
Responsible disclosure means reporting vulnerabilities privately to our security team, allowing reasonable time for remediation before public disclosure, and avoiding data exfiltration, system disruption, or privacy violations during testing.
While not mandatory, we strongly encourage PGP encryption for all submissions containing sensitive information. If you submit without encryption, our team will still handle your report with strict confidentiality protocols.