Security, Transparency & Trust
Aevum Zenth maintains rigorous security standards across all 400 subsidiaries. We are committed to responsible disclosure, rapid incident response, and full regulatory compliance.
🛡️ Vulnerability Disclosure Policy (VDP)
We welcome security researchers to help us identify and remediate vulnerabilities. Our VDP applies to all Aevum Zenth domains, applications, APIs, IoT endpoints, and physical security systems operating under our brand.
✅ In Scope
- All *.aevumzenth.com & *.zenth.global domains
- Public-facing APIs, SDKs, & mobile applications
- Cloud infrastructure & container orchestration layers
- Hardware endpoints & IoT telemetry channels
- Authentication, authorization & session management
🚫 Out of Scope
- Denial of Service (DoS) or DDoS attacks
- Social engineering, phishing, or physical intrusion
- Automated scanning without prior written authorization
- Vulnerabilities in third-party services outside our control
- Cosmetic UI issues or non-security functionality bugs
⚖️ Safe Harbor & Legal Protection
Researchers acting in good faith and following our disclosure guidelines will not face legal action. We grant explicit permission for non-disruptive testing within scope. Do not access, modify, or delete user data, and cease testing immediately upon reaching a production environment boundary.
⏱️ Response SLA & Triage Workflow
Our Security Operations Center (SOC) operates 24/7/365. Vulnerability reports are triaged, validated, and routed to the appropriate engineering division.
Receipt & Acknowledgment
Report logged, assigned a tracking ID, and confirmed within 24 hours. PGP-encrypted channels preferred.
Validation & Triage
SOC engineers verify proof-of-concept, determine severity (CVSS v3.1), and route to the affected division.
Remediation & Patching
Engineering implements fixes, conducts regression testing, and deploys across production/staging environments.
Verification & Closure
Researcher verifies fix, public disclosure coordinated, and bounty/acknowledgment issued per severity tier.
📜 Compliance & Certifications
Aevum Zenth maintains continuous compliance across multiple regulatory frameworks to protect data, infrastructure, and customer trust.
🔒 Data & Privacy
GDPR, CCPA, HIPAA (Health Sciences division), and SOC 2 Type II certified. Automated DLP pipelines and zero-trust data access controls enforce least-privilege principles.
🏗️ Infrastructure & Operations
ISO 27001, ISO 22301 (Business Continuity), NIST CSF, and FedRAMP Moderate (Aerospace & Gov contracts). Annual third-party penetration tests and red-team exercises.
🔍 Audit Transparency
Compliance audit reports, penetration test summaries (redacted), and security architecture diagrams are available to enterprise clients under NDA. Request via our compliance portal.
📩 How to Report
Submit vulnerability reports, security inquiries, or compliance requests through our dedicated encrypted channels.
Public PGP Key (Fingerprint: A8F2 9C41 D7B3 0E12 4A5F 8C90 2D11 7E34 B9A6 00Z2)
mQINBF2...
wF... [TRUNCATED FOR DISPLAY] ...9K
-----END PGP PUBLIC KEY BLOCK-----