# Axeon Prime Vulnerability Disclosure Policy (VDP)

At Axeon Prime, we believe that robust cybersecurity requires collaboration with the global security research community. We have designed our automated AI consultancy platform and Sovereign Infrastructure with security as a foundational principle. 

**FLASH BOUNTY NOTICE:** We are issuing a strict 24-hour challenge to security researchers to test our defenses. This challenge will run for exactly 24 hours from the time of announcement. If you believe you have found a security vulnerability in our systems during this window, we encourage you to report it to us in accordance with this policy. We will work with you to resolve the issue promptly and reward validated findings.

## Safe Harbor

Axeon Prime considers activities conducted consistent with this policy to constitute "authorized" conduct. We will not initiate legal action or law enforcement investigation against you for accidental, good-faith violations of this policy. 

To remain within safe harbor, you must:
* Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data.
* Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.
* Do not subject Axeon Prime employees, clients, or physical facilities to social engineering (e.g., phishing, vishing), physical attacks, or distributed denial of service (DDoS) attacks.
* Keep information about any vulnerabilities you've discovered confidential between yourself and Axeon Prime until we have resolved the issue.

## In-Scope Systems

The following targets are explicitly in-scope for this challenge:
* **The Axeon Prime Gateway:** `https://axeon-prime.com`
* **The Modal Backend Services:** Any `.modal.run` endpoints directly associated with the Axeon Prime infrastructure.

## Out-of-Scope Systems

The following targets and vulnerability classes are strictly out-of-scope:
* **The VelocityVault:** Any attempts to access, manipulate, or extract funds from the underlying financial infrastructure (Stripe/Google Wallet integration) are strictly prohibited and fall outside of safe harbor.
* **KVANTA-alpha:** The dark pool memory storage layer is strictly isolated.
* Third-party applications, APIs, or services not directly owned or operated by Axeon Prime (e.g., Cloudflare infrastructure itself).
* Denial of Service (DoS / DDoS) attacks.
* Social engineering or phishing attempts against Axeon Prime personnel or clients.

## Reporting a Vulnerability

If you believe you have found a qualifying vulnerability, please submit a detailed report to **security@axeonprime.com**. 

Your report must include:
* A clear description of the vulnerability and its potential impact.
* Detailed, step-by-step instructions to reproduce the issue (including any necessary scripts or proof-of-concept code).
* The date and time the testing was conducted.

## Bounties

Axeon Prime offers financial bounties for actionable, in-scope vulnerability reports. Bounties are awarded at our discretion based on the severity and impact of the vulnerability, utilizing the CVSS 3.1 scoring system as a baseline. 

* **Critical (e.g., RCE, SQLi, Auth Bypass):** Up to $50,000 USD
* **High (e.g., Stored XSS, Privilege Escalation):** Up to $20,000 USD
* **Medium (e.g., Reflected XSS, CSRF):** Up to $5,000 USD
* **Low:** Hall of Fame recognition

*Note: All bounties are paid via standard B2B invoice processing. Axeon Prime reserves the right to modify this policy at any time.*
