ADT — Aetheron Deep Tech
Security

Security & Vulnerability Disclosure

A responsible route for reporting security issues affecting Aetheron-controlled systems, with clear boundaries for good-faith research.

Effective 11 September 2026Last updated 11 September 2026

Purpose

Aetheron values responsible reporting of genuine security issues. This policy explains how to report a potential vulnerability affecting a system that Aetheron controls and the conditions under which we consider security research to be conducted in good faith.

This policy is not a bug-bounty program and does not promise payment, reward, employment or public recognition. Any reward would need to be separately agreed in writing.

How to report an issue

Email hello@aetherondeeptech.com with the subject line 'Security Vulnerability Report'. Include the affected hostname or asset, a concise description, steps needed to reproduce the issue, the potential impact, relevant screenshots or logs, and a safe way to contact you for follow-up.

Do not include passwords, private keys, access tokens, personal data, customer confidential information or exploit data that is not necessary to understand the report. If highly sensitive evidence is essential, first ask us for a suitable secure exchange method.

Systems in scope

Unless Aetheron identifies a broader scope in writing, this policy applies only to publicly reachable web assets and services that are directly controlled by Aetheron Deep Tech Private Limited and clearly use the aetherondeeptech.com domain or another domain that Aetheron has expressly identified as in scope.

Third-party services, infrastructure operated by customers or partners, social-media platforms, cloud-provider control planes, internet service providers and systems that merely contain an Aetheron account are not in scope unless we have authority to authorize testing and explicitly say so.

Good-faith research expectations

Security testing should be proportionate, minimally invasive and limited to what is necessary to demonstrate the issue. Stop when you have enough evidence to report the vulnerability safely.

  • Avoid accessing, copying, downloading, altering, deleting or retaining another person's data beyond the minimum unavoidable evidence required to demonstrate the issue.
  • Do not establish persistence, plant malware, create backdoors, pivot into unrelated systems or attempt to maintain unauthorized access.
  • Do not degrade availability, overload infrastructure or perform denial-of-service, stress testing or destructive testing.
  • Do not conduct social engineering, phishing, credential theft, physical intrusion or attacks against personnel, contractors, customers or suppliers.
  • Do not use automated scanning that creates excessive traffic or interferes with normal service.
  • Comply with applicable law and do not intentionally violate third-party rights or contractual restrictions.

Sensitive findings and personal data

If you unexpectedly encounter credentials, personal data, confidential client information or other sensitive material, stop testing, do not disclose the information to anyone else, do not retain more than necessary to make the report, and notify us promptly. We may ask you to delete or securely return copies after the issue is understood.

Coordinated disclosure

Please give Aetheron a reasonable opportunity to investigate and remediate a vulnerability before publishing technical details that could materially increase risk to users, customers or systems. We may ask for temporary confidentiality while remediation is underway. We will try to keep a reporting researcher informed about meaningful progress where doing so does not create additional security or legal risk.

Aetheron does not require indefinite secrecy. If coordinated public disclosure is appropriate, timing and content should be discussed in good faith after remediation or risk mitigation is available.

Our response

We aim to acknowledge credible reports, assess severity and prioritize remediation according to practical risk. Response time depends on the complexity and impact of the issue. A report may be closed without action if it is not reproducible, is out of scope, has negligible security impact or describes behaviour that is intentionally part of the system design.

Good-faith safe-harbour position

Subject to applicable law, Aetheron does not intend to pursue legal action solely because a researcher conducted security testing in good faith and in a manner consistent with this policy. This statement cannot authorize conduct on systems Aetheron does not own or control and does not bind third parties, regulators or law-enforcement authorities.

If you are unsure whether a proposed test is safe or authorized, contact us before performing it. Written authorization for a specific test scope may be appropriate for activities that would otherwise create material risk or uncertainty.

Not security support for client systems

This disclosure channel is for vulnerabilities in Aetheron-controlled assets. A customer should use the support, security or incident channel specified in its contract for issues relating to a customer deployment or production engagement. Nothing in this public policy expands the support or security obligations in a client agreement.

Contact

Security reports should be sent to hello@aetherondeeptech.com with the subject 'Security Vulnerability Report'. For urgent issues, include 'URGENT' only when there is a credible risk of active exploitation, material data exposure or significant service disruption.