Aeion OS Security Disclosure Program.

Aeion treats vulnerability disclosure as a shared responsibility with the security community. Researchers who report in good faith get acknowledgment within 24 hours, a fix-or-mitigation timeline within 7 days, and a non-prosecution commitment that covers reasonable testing methods. Confirmed vulnerabilities are eligible for monetary recognition. The full rules of engagement, scope, and reporting process — on this page.

Coordinated disclosure program · public scope
Non-prosecution commitment for good-faith researchers
24-hour acknowledgment of reports
7-day fix-or-mitigation timeline communication
Public credit + monetary recognition for confirmed vulnerabilities
Annual third-party penetration test
Continuous internal red-team exercises
Incident response with 1-hour critical-detection SLA
72-hour customer notification per GDPR Article 33

How to Report a Vulnerability

The fastest, most secure path is email.

Scope — What's In and What's Out

The scope below is intentionally generous. When in doubt, ask before testing.

Rules of Engagement

Test in good faith. We commit to non-prosecution for researchers who follow the rules below.

Monetary Recognition

Aeion's formal bug-bounty program is in progress; the page you're reading documents the interim posture. Until the formal program launches, confirmed unique vulnerabilities are eligible for reasonable monetary recognition, scaled to severity.

Incident Response Posture

What happens when something goes wrong.

Security Advisories

When we ship a security-relevant change, we publish an advisory. Most security work doesn't merit an advisory (routine library updates, internal hardening) — advisories are reserved for changes that customers should know about.

Frequently Asked Questions

No public date yet. Until it launches, the disclosure program described on this page covers the same posture (acknowledgment SLA, non-prosecution, monetary recognition for confirmed vulnerabilities). The formal program will add a bounty platform (HackerOne or Bugcrowd) and refined scope; until then, email is the canonical channel.

Tell us first, not the customer. We coordinate with affected customers as part of the disclosure process. Going to the customer first creates an asymmetric-disclosure problem that hurts everyone.

No — those go to the third party's disclosure program. We help researchers connect with the right teams at AWS / Stripe / OpenAI / etc. if you're not sure where to report.

Reproducible by our security team in a controlled environment, not already known to us (we maintain an internal disclosure log), and not previously reported by another researcher. Duplicate reports get acknowledgment but not bounty.

Under NDA. Enterprise customers get the full report; Professional customers get an executive summary. The annual third-party pen test is part of our standard security review packet at /trust.

Yes — book a Security Review at /contact. 60 minutes with our security lead; we ship a full security packet within 5 business days afterward.

Yes — for issues that meet CVE criteria, we coordinate CVE assignment through MITRE. The advisory references the CVE.

Email founders@aeionos.com after your initial security@aeionos.com submission if you're not getting timely response. That goes directly to our CEO/CTO.

Researchers who follow the rules-of-engagement get non-prosecution commitment in writing. We won't pursue legal action, won't report you to law enforcement, won't suspend your sandbox tenant for good-faith testing. The commitment covers DMCA, CFAA (US), and equivalent statutes globally.

Yes — prompt injection is in scope. We're particularly interested in: cross-tenant prompt-injection (an AI conversation in one tenant influencing another), prompt-injection that leaks tenant data, prompt-injection bypassing RBAC, and persistence attacks (injection that survives across sessions).

Also in scope. WebMCP tools should respect tenant + user RBAC; any path that allows a browser to invoke a tool beyond the user's permissions is a high-priority report.

Specifically in scope. Backup-key recovery attacks, restore-path race conditions, object-lock bypass, cross-tenant backup access — all high-priority. The Aegis architecture is documented at /platform/aegis.