Overview
At Aevum News, data security is not an afterthought—it is foundational to our journalistic integrity and public trust. This document outlines our comprehensive security architecture, data handling protocols, and legal commitments to protecting reader information, confidential sources, and internal editorial systems.
Our Commitment
We adhere to zero-knowledge privacy principles wherever possible, implement military-grade encryption for data in transit and at rest, and maintain strict access controls that segregate editorial, technical, and administrative functions.
Data Collection & Scope
We collect only what is strictly necessary to deliver our service, maintain platform security, and comply with legal obligations. All data processing is documented, minimized, and subject to regular retention reviews.
- Essential Analytics: Aggregated, anonymized traffic metrics to improve content delivery and user experience.
- Account Data: Encrypted credentials, subscription preferences, and communication logs (only when explicitly opted-in).
- Security Logs: IP-based threat monitoring, failed login attempts, and automated bot detection mechanisms.
- Exclusions: We do not sell personal data, do not use third-party advertising trackers, and do not cross-reference reader data with external databases.
Encryption & Infrastructure
Our technical infrastructure is built on defense-in-depth principles, utilizing industry-standard cryptographic protocols and geographically distributed security controls.
All database communications utilize mutual TLS authentication. Internal microservices are isolated via zero-trust networking architecture. Backup systems are air-gapped and encrypted with rotating key management protocols.
Source & Journalist Protection
Protecting confidential sources is a legal and ethical imperative. Aevum News employs dedicated secure communication channels that leave no metadata trail.
- Secure Drop Portal: End-to-end encrypted submission system using Tor integration and ephemeral key exchange.
- Metadata Stripping: All uploaded files are automatically sanitized of EXIF, geolocation, and authorship traces.
- Access Segregation: Source materials are stored in isolated vaults. Only assigned editors can decrypt and access submissions.
- Legal Shield: Our editorial team is trained in press freedom statutes and data protection exemptions applicable to journalistic activities.
User Rights & Control
Readers retain full sovereignty over their personal data. We provide transparent, accessible tools for data management in compliance with GDPR, CCPA, and international privacy frameworks.
- Access & Export: Download a complete archive of your account data in standard formats (JSON/CSV/PDF).
- Correction: Update or rectify inaccurate information directly through your dashboard.
- Deletion: Request full account and data erasure. Processing occurs within 14 business days.
- Opt-Out: Disable all non-essential processing, including analytics and personalized content features.
Compliance & Audits
Aevum News undergoes regular third-party security assessments and maintains certifications aligned with global information security standards.
Current Certifications & Frameworks
ISO 27001:2022 (Information Security Management), SOC 2 Type II Compliance, GDPR Article 28 DPA Adherence, NIST Cybersecurity Framework v2.0 alignment, and biannual penetration testing by accredited red teams.
Internal audits are conducted quarterly by our dedicated Privacy & Security Board. Findings are documented, remediated within defined SLAs, and tracked to closure.
Incident Response Protocol
Despite rigorous preventive measures, we maintain a structured incident response framework to detect, contain, and remediate security events swiftly.
- Detection: Automated threat intelligence feeds, anomaly detection algorithms, and real-time log correlation.
- Containment: Immediate isolation of affected systems, credential rotation, and traffic rerouting.
- Notification: Affected users and regulatory bodies are notified within 72 hours of confirmed data compromise, as mandated by law.
- Forensics: Full chain-of-custody preservation, root-cause analysis, and post-incident hardening implementation.
Frequently Asked Questions
Security Inquiries & Reporting
Report vulnerabilities, request security documentation, or contact our Privacy Office directly. All submissions are handled with strict confidentiality.
Contact Security Team