Reporting Guidelines

  • Do not exploit or access data beyond what's necessary to prove the vulnerability
  • Avoid automated scanners that impact system availability
  • Do not download, modify, or delete user/company data
  • Submit one report per unique vulnerability

Severity Classification

  • Critical: Remote code execution, full data breach, complete system compromise
  • High: Privilege escalation, sensitive data exposure, payment bypass
  • Medium: Authenticated XSS, limited data leakage, business logic flaws
  • Low: Information disclosure, missing headers, minor UI/UX security gaps

PGP Key for Encrypted Reports

For highly sensitive disclosures, encrypt your report using our public key:

mQINBGK8x6wBEACxR3Jk9mF7vY2hP9LqT8NwZ4XcV1Rk...truncated for display

Response Timeline

  • Initial Acknowledgment: Within 24 hours
  • Triage & Validation: 3-5 business days
  • Resolution/Patch: Varies by severity (Critical: <72hrs)
  • Closure & Attribution: 14-30 days post-fix

This form is transmitted over TLS 1.3. All submissions are encrypted at rest and processed exclusively by the Aevum Zenth Security Operations Center (SOC).

Submit Vulnerability Report

Drag & drop files here, or browse

Max 25MB. PDF, PNG, JPG, TXT, PCAP only.

Report Submitted Successfully

Your disclosure has been encrypted and routed to our SOC. You will receive an acknowledgment at your provided email within 24 hours. Reference ID:

1

Receive & Acknowledge

Your report is automatically ticketed, encrypted, and acknowledged within 24 hours.

2

Triage & Validation

Our threat analysis team validates the claim, reproduces the issue, and assigns priority.

3

Investigate & Remediate

Engineering patches the vulnerability while maintaining system integrity and compliance.

4

Closure & Attribution

You're notified of the fix. We honor responsible disclosure credits and bug bounty eligibility.