Security Reporting & Responsible Disclosure
We take the security of our infrastructure, assets, and global operations seriously. If you've discovered a vulnerability, please report it through our secure channel below.
Reporting Guidelines
- Do not exploit or access data beyond what's necessary to prove the vulnerability
- Avoid automated scanners that impact system availability
- Do not download, modify, or delete user/company data
- Submit one report per unique vulnerability
Severity Classification
- Critical: Remote code execution, full data breach, complete system compromise
- High: Privilege escalation, sensitive data exposure, payment bypass
- Medium: Authenticated XSS, limited data leakage, business logic flaws
- Low: Information disclosure, missing headers, minor UI/UX security gaps
PGP Key for Encrypted Reports
For highly sensitive disclosures, encrypt your report using our public key:
Response Timeline
- Initial Acknowledgment: Within 24 hours
- Triage & Validation: 3-5 business days
- Resolution/Patch: Varies by severity (Critical: <72hrs)
- Closure & Attribution: 14-30 days post-fix
This form is transmitted over TLS 1.3. All submissions are encrypted at rest and processed exclusively by the Aevum Zenth Security Operations Center (SOC).
Submit Vulnerability Report
Report Submitted Successfully
Your disclosure has been encrypted and routed to our SOC. You will receive an acknowledgment at your provided email within 24 hours. Reference ID:
Receive & Acknowledge
Your report is automatically ticketed, encrypted, and acknowledged within 24 hours.
Triage & Validation
Our threat analysis team validates the claim, reproduces the issue, and assigns priority.
Investigate & Remediate
Engineering patches the vulnerability while maintaining system integrity and compliance.
Closure & Attribution
You're notified of the fix. We honor responsible disclosure credits and bug bounty eligibility.