01 Source & Journalist Protection

Protecting whistleblowers, anonymous sources, and field journalists is foundational to our editorial mission. We implement encrypted communication channels and strict operational security (OPSEC) protocols to prevent identification or retaliation.

Core Principle: Source anonymity is legally and technically guaranteed unless explicitly waived by the source or required by court order, which we will challenge to the fullest extent permitted by law.

02 Data Encryption & Secure Infrastructure

All sensitive data at rest and in transit is protected using AES-256 encryption and TLS 1.3 protocols. Our infrastructure is distributed across geographically isolated servers to prevent single-point failures or unauthorized access.

🔐 At-Rest Encryption

Database volumes, backups, and archival storage utilize AES-256 with hardware-backed key management.

🌐 In-Transit Security

All user traffic and internal API communications are enforced over TLS 1.3 with HSTS enabled.

🏢 Isolated Workstations

Editorial and legal teams operate on air-gapped or VPN-isolated machines for handling classified materials.

03 Access Control & Authentication

Access to internal systems follows the principle of least privilege. Multi-factor authentication (MFA) is mandatory for all staff, contractors, and third-party integrations. Role-based access control (RBAC) ensures journalists only access materials relevant to their assignments.

04 Compliance & Data Privacy Standards

Aevum News adheres to international data protection regulations including GDPR, CCPA, and local press freedom laws. We maintain a Data Protection Officer (DPO) and conduct annual third-party compliance audits.

Transparency Commitment: We publish an annual transparency report detailing government data requests, legal challenges, and our response actions, in alignment with press freedom advocacy standards.

05 Incident Response & Cyber Resilience

In the event of a security breach or cyber incident, Aevum News activates a predefined incident response plan within 60 minutes. Our team maintains regular communication channels with independent cybersecurity firms and legal counsel.