Back to Home
AIONTECH
TRANSPARENCY | DISCLOSURE | SECURITY

SECURITY ADVISORIES

COMMITTED TO RESPONSIBLE DISCLOSURE

All Systems Secure

No active critical advisories

0
Critical
0
High
0
Medium
0
Low

Last Updated: January 5, 2025

SEVERITY LEVELS

Understanding our advisory classification system

Critical

Immediate action required. Severe risk of compromise.

High

Action required within 24 hours. Significant security risk.

Medium

Action required within 7 days. Moderate security risk.

Low

Action required within 30 days. Minor security risk.

RECENT ADVISORIES

Latest security updates and patches

mediumSA-2024-12-001

Platform Update - Session Management Enhancement

December 18, 2024
resolved

Summary

Updated session management to prevent potential session fixation attacks.

Impact

Low risk. No known exploitation. Preventative measure.

Required Action

No action required. Auto-deployed to hosted services. Self-hosted: update to v2.4.1+

highSA-2024-11-002

Third-Party Dependency Update - Log4j Variant

November 5, 2024
resolved

Summary

Proactive update of logging framework addressing potential vulnerability.

Impact

No impact to AionTech services. Precautionary update applied.

Required Action

SDK users: update to v3.2.0 or higher.

DISCLOSURE POLICY

How we handle security vulnerabilities

Responsible Disclosure

We welcome reports from security researchers. If you discover a vulnerability:

  • Report privately to security@aiontech.com
  • Do not exploit or access data without permission
  • Allow reasonable time for investigation and remediation
  • Coordinate public disclosure timeline with us

Response Timeline

Initial Response

Within 24 hours

Triage & Validation

Within 72 hours

Critical Remediation

Within 7 days

High Remediation

Within 14 days

BUG BOUNTY PROGRAM

Rewarding responsible security research

Critical
$2,500 - $10,000

Remote code execution, authentication bypass

High
$1,000 - $5,000

SQL injection, XSS, privilege escalation

Medium
$500 - $2,000

CSRF, information disclosure

Low
$100 - $500

Rate limiting issues, minor vulnerabilities

Scope & Eligibility

In Scope

  • AionTech web applications
  • Mobile applications (iOS/Android)
  • APIs and web services
  • Client-side libraries and SDKs

Out of Scope

  • Third-party services
  • Social engineering attacks
  • Physical attacks
  • DDoS attacks

SECURITY BEST PRACTICES

Recommendations for clients

Enable MFA

Multi-factor authentication on all accounts

Rotate Keys

API keys every 90 days minimum

Monitor Logs

Regular review of access and activity logs

Update Systems

Keep all systems and dependencies current

Report a Vulnerability

Help us keep our systems secure by responsibly disclosing vulnerabilities

security@aiontech.com

Response time: <24 hours | 24/7 Emergency Hotline: +1 (555) SECURE-1