AETHERION CYBER SYSTEMS

✦ Coordinated Vulnerability Disclosure Policy (VDP) ✦

← RETURN TO PORTAL
RFC 9116 Compliant Policy

Commitment to Sovereign Security & Safe Harbor

Aetherion Cyber Systems welcomes responsible vulnerability disclosures from security researchers worldwide. We are committed to working collaboratively to address potential vulnerabilities and protect customer and clinical enclaves.

1. Reporting & Cryptographic PGP Custody

Please encrypt all vulnerability reports using the official company PGP key:

Fingerprint: CB08 862E 84EA BCCC 8515 2E70 3CF5 126B BBAF E64C

2. In-Scope & Out-of-Scope

In-Scope

  • https://aetherioncyber.com
  • https://*.aetherioncyber.com
  • P.H.A.L.A.N.X. MDR & Kairos NDR APIs
  • C.I.T.A.D.E.L. SOC Gateway

Out-of-Scope

  • Volumetric DoS/DDoS
  • Physical security & hardware tampering
  • Phishing or social engineering
  • Destruction of customer enclave data

3. Legal Safe Harbor Commitment

Aetherion Cyber Systems considers good-faith security research conducted under this policy to be authorized under the Computer Fraud and Abuse Act (CFAA) and will not pursue legal action against researchers acting in good faith.

4. Response Timelines

≤ 24 Hours Acknowledgment
≤ 72 Hours Triage
≤ 30 Days Remediation

5. Acknowledgments

Researchers who discover verified vulnerabilities in accordance with this policy will be acknowledged in our Hall of Fame upon mutual coordinated disclosure.