Our Commitment to Data Integrity
At Aevum News, data security is not just an IT requirement—it is a journalistic imperative. Protecting source identities, safeguarding editorial databases, and ensuring the integrity of our archival records are foundational to our mission. We maintain a zero-trust architecture, enforce strict access controls, and undergo continuous third-party audits to guarantee that sensitive information remains confidential and unalterable.
Transparency Pledge: We publish our security practices openly so our readers, sources, and partners can verify our commitment to responsible data handling.
Security Architecture & Protocols
End-to-End Encryption
All data in transit uses TLS 1.3. Data at rest is encrypted with AES-256-GCM. Encryption keys are rotated quarterly and managed via HSMs.
Zero-Trust Access
Role-based access control (RBAC), mandatory MFA, and just-in-time privileges ensure only authorized personnel reach sensitive systems.
Immutable Backups
Archival content and editorial drafts are stored in WORM-compliant storage to prevent unauthorized modification or deletion.
Threat Detection & Response
24/7 SOC monitoring, SIEM integration, and automated incident playbooks ensure rapid containment of potential breaches.
Storage Infrastructure
Our multi-region cloud infrastructure ensures high availability and geographic redundancy. Editorial databases, media assets, and secure source communications are distributed across isolated environments with strict network segmentation.
| Component | Specification | Uptime SLA |
|---|---|---|
| Primary Storage | Geo-redundant cloud object storage | 99.99% |
| Database Clusters | Encrypted, multi-AZ PostgreSQL & Redis | 99.95% |
| Backup Retention | 30-day incremental, 7-year immutable archive | 100% |
| Disaster Recovery | Hot standby in secondary region, RPO < 5min | 99.9% |
Compliance & Certifications
Aevum News adheres to internationally recognized data protection and information security standards. Our compliance framework is reviewed annually by independent auditors.
- GDPR & CCPA: Full compliance with data minimization, right to access, and cross-border transfer safeguards.
- ISO/IEC 27001: Certified Information Security Management System (ISMS) covering all editorial and operational data flows.
- SOC 2 Type II: Independent verification of security, availability, and confidentiality controls.
- Editorial Standards: Alignment with IFJ Guidelines on Source Protection and Data Ethics in Journalism.
Source Protection & Secure Communications
We operate dedicated secure drop systems compatible with Tails, Signal, and encrypted email. All source materials are isolated from production databases, accessible only to assigned editors with verified clearance. Metadata is stripped upon ingestion, and retention schedules strictly follow legal and journalistic best practices.
Need to submit confidential information? Use our secure portal or contact our source protection team via encrypted channels. We never pressure sources to reveal identifying details.
Incident Response & Transparency
In the event of a security incident, Aevum News follows a documented incident response plan. We commit to notifying affected parties within 72 hours, cooperating with relevant authorities, and publishing post-incident reviews to maintain trust and accountability.