Security & Data Retention

Our commitment to protecting user data, securing content infrastructure, and maintaining transparent retention standards.

Last updated: November 15, 2025

Our Commitment to Security

At Aevum News, safeguarding your data and maintaining the integrity of our publishing infrastructure are foundational to our mission. We employ industry-leading security protocols, continuous monitoring, and strict access controls to ensure that reader information, subscriber data, and editorial content remain protected against unauthorized access, alteration, or destruction.

Our security framework is reviewed quarterly by independent third-party auditors and updated to address emerging threats in digital journalism and data handling.

Security Measures

We implement a multi-layered defense strategy across all digital assets, user platforms, and internal systems:

🔒

End-to-End Encryption

All data in transit uses TLS 1.3, and sensitive data at rest is encrypted with AES-256 standard.

🛡️

Zero-Trust Architecture

Strict identity verification and least-privilege access controls for all internal and API endpoints.

🌐

DDoS & WAF Protection

Cloud-native web application firewalls and traffic scrubbing to maintain uptime during attacks.

👁️

24/7 SOC Monitoring

Real-time threat detection, log analysis, and automated incident playbooks run around the clock.

We also conduct regular penetration testing, vulnerability scans, and mandatory security training for all editorial and technical staff.

Content & Data Retention Policy

We retain data only as long as necessary to fulfill operational, legal, and archival purposes. All retention periods are strictly enforced via automated lifecycle management.

Data/Content Type Retention Period Purpose & Disposition
Published Articles & Media Indefinite Preserved for public record. Archived via immutable storage with version control.
User Account Data Duration of account + 24 months Retained for support, analytics, and legal compliance. Securely wiped upon deletion request.
Comments & UGC 7 years Moderated and stored for community standards enforcement. Anonymized after period.
Payment & Subscription Logs 7 years Maintained per financial regulations and tax requirements. Encrypted at rest.
Analytics & Cookies 13 months Aggregated and pseudonymized for service improvement. Auto-purged via lifecycle rules.
Editorial Drafts & CMS Logs 3 years Retained for audit trails and version recovery. Purged securely thereafter.

Users may request data export or permanent deletion at any time through their account dashboard or by contacting our privacy team. All deletion requests are processed within 30 business days.

Compliance & Certifications

Aevum News adheres to global data protection standards and regularly audits our practices to ensure ongoing compliance:

GDPR Compliant
CCPA/CPRA Aligned
SOC 2 Type II Certified
ISO 27001 Audited
News Media Ethics Charter Signatory

We maintain a Data Processing Addendum (DPA) for all vendors and third-party integrations. Cross-border data transfers utilize Standard Contractual Clauses (SCCs) and localized storage where required by law.

Incident Response & Transparency

In the event of a security incident or data breach, our dedicated Security Operations Center (SOC) follows a documented response protocol:

  • Detection & Containment: Automated alerts trigger immediate isolation of affected systems.
  • Assessment & Forensics: Internal and external experts analyze scope, impact, and root cause.
  • Notification: Affected users and regulatory bodies are notified within 72 hours where legally required.
  • Remediation & Review: Systems are patched, policies updated, and a public post-incident report published within 14 days.

We believe in radical transparency. All confirmed incidents, response timelines, and mitigation steps are documented in our public security status page.

Contact & Reporting

If you have questions about our security practices, wish to submit a data request, or need to report a vulnerability, please reach out to our dedicated team:

Security & Privacy Inquiries

For all data retention, privacy, or security concerns:

PGP Key available for encrypted communications: Download Public Key

Bug Bounty Program: Submit Vulnerability →