Legal
Security Policy
Last Updated: July 7, 2026
Aevius Labs takes the security of its products and services seriously. This policy explains how to report a security vulnerability and what to expect in return.
Reporting a vulnerability
Email: security@aevius.ai
This mailbox is monitored and is the primary channel for reporting a suspected security vulnerability in any Aevius product or service. If you wish to encrypt your report, request our PGP key at the same address.
Please include, where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept, affected component or version)
- Any relevant references — with all sensitive or customer data redacted
What you can expect from us
If you share your contact information, we will coordinate with you as openly and as quickly as we can:
- We will acknowledge receipt within 2 business days (faster for a credible, critical report).
- We will confirm the vulnerability to the best of our ability and keep you informed as we work toward a fix, including on anything that may delay resolution.
- We prioritize remediation on a risk basis, by severity and impact.
- We will notify you when the issue is resolved.
We practice coordinated disclosure: we will credit reporters who wish to be acknowledged, and we ask that you give us a reasonable opportunity to remediate before any public disclosure. We do not operate a paid bug bounty at this time.
Ground rules
- Do not include sensitive data, customer data, or credentials in a report. If a vulnerability can only be demonstrated with such data, describe it abstractly and we will coordinate.
- Please avoid privacy violations, data destruction, and service degradation while researching.
- Social engineering, physical attacks, and denial-of-service testing are out of scope.
Safe harbor
We will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy, make a good-faith effort to avoid privacy violations and data destruction, and give us reasonable time to respond before disclosure.