We protect our journalists, our sources, and our readers. Every layer of Aevum News is engineered for resilience, privacy, and transparency.
Security isn't a featureβit's our foundation. Every system, process, and policy is designed around trust.
All data in transit and at rest is encrypted using AES-256 and TLS 1.3. Source communications are protected with PGP and secure drop infrastructure.
Data ProtectionNo implicit trust, anywhere. Every access request is verified, authenticated, and authorized. Micro-segmentation isolates critical editorial systems.
Infrastructure24/7 threat detection, log analysis, and anomaly response. Our SOC operates around the clock to neutralize threats before they impact operations.
OperationsWe maintain strict compartmentalization, encrypted storage, and minimal data retention policies to protect journalistic sources at all costs.
JournalismAutomated playbooks, rapid containment protocols, and transparent post-incident reporting. We prepare for breaches so we never suffer from them.
ResilienceAnnual penetration testing, code reviews, and third-party security assessments. We invite scrutiny to ensure our promises hold.
VerificationWe welcome responsible security researchers. Help us keep Aevum News secure.
Send detailed findings to our security team via encrypted channels. Include reproduction steps, impact, and affected endpoints.
We respond within 24 hours. Valid reports are assigned a tracking ID and prioritized by severity (Critical, High, Medium, Low).
Our engineering team patches vulnerabilities within agreed timelines. We keep reporters updated on progress.
Once fixed, we confirm closure and publicly acknowledge contributors in our security hall of fame (with permission).
To ensure your report is handled properly, please follow these guidelines:
We adhere to globally recognized security and privacy frameworks.
Full data protection alignment for EU readers. Explicit consent, right to erasure, and data portability enforced.
Certified Information Security Management System. Regular surveillance audits ensure continuous compliance.
Independent verification of security, availability, processing integrity, confidentiality, and privacy controls.
California consumer privacy rights fully implemented. Opt-out mechanisms and data mapping actively maintained.
Real-time visibility into our critical systems and recent security events.
| System / Component | Status | Last Incident | Uptime (30d) |
|---|---|---|---|
| CDN & Edge Network | Operational | None | 99.998% |
| Secure Drop Portal | Operational | 2024-11-12 | 99.999% |
| Editorial CMS | Operational | 2024-09-03 | 99.97% |
| Authentication Services | Operational | None | 99.995% |
| Database Clusters | Operational | 2024-08-19 | 99.99% |
Have a concern or discovered a vulnerability? Use the form below or email security@aevumnews.com