1. Information Security Commitment
We operate a zero-trust security architecture across all publishing, editorial, and reader-facing platforms. Our security program is continuously audited and aligned with international standards including ISO 27001 and NIST CSF.
Confidentiality • Integrity • Availability • Transparency • Accountability
- Continuous monitoring of all production environments
- Automated threat detection with AI-assisted anomaly analysis
- Mandatory security training for all staff and contractors
- Regular third-party penetration testing and code audits
2. Data Protection & Privacy
We collect only what is necessary to deliver our service and enhance reader experience. All personal data is processed in strict compliance with GDPR, CCPA, and applicable regional regulations.
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Retention: Data is anonymized or deleted after 24 months of inactivity
- Consent: Explicit opt-in for non-essential tracking; granular cookie controls
- Reader Rights: Full access, correction, portability, and deletion requests honored within 30 days
3. Vulnerability Disclosure Program
We actively welcome responsible disclosure from security researchers. If you discover a vulnerability in our infrastructure, please report it through our official channels. We operate under a safe harbor policy for good-faith researchers.
Send detailed reports to: security@aevumnews.com
PGP Key available at pgp.mit.edu
Response SLA: Acknowledgment within 48 hours | Resolution within 30 days
- Do not access, modify, or exfiltrate user data during testing
- Avoid automated scanning during peak hours (08:00–18:00 UTC)
- Disclose findings privately before public disclosure
- Ethical researchers may be eligible for our bug bounty program
4. Access Control & Authentication
Access to internal systems, editorial CMS, and infrastructure is strictly governed by the principle of least privilege.
- Mandatory Multi-Factor Authentication (MFA) for all staff, contractors, and third-party vendors
- Role-Based Access Control (RBAC) with quarterly permission audits
- Session timeouts after 15 minutes of inactivity on sensitive systems
- Hardware security keys (FIDO2) required for administrative and publishing accounts
5. Incident Response & Transparency
In the event of a security incident, our dedicated Security Operations Center (SOC) follows a defined playbook to contain, investigate, and remediate threats rapidly.
- 24/7 SOC monitoring with automated alerting
- Incident classification: Low, Medium, High, Critical
- Affected users and regulators notified within legally mandated timeframes
- Public post-mortem reports published for incidents impacting reader data or platform integrity
6. Third-Party & Vendor Security
Every partner, SaaS provider, and data processor undergoes rigorous security vetting before integration. We maintain active Data Processing Agreements (DPAs) and conduct annual compliance reviews.
Allowed integrations are limited to: CDNAnalyticsPayment ProcessingEmail DeliveryCMS Hosting
7. Contact & Support
For security inquiries, vulnerability reports, or compliance requests, please contact our dedicated security team:
Email: security@aevumnews.com
Privacy & Data Requests: privacy@aevumnews.com
PGP Fingerprint: 4A9F 2B1E 8C0D 76F3 A9E2 1B5D 9042 78C6 F1E3 8290
We are committed to responding promptly and maintaining open communication with all stakeholders regarding security matters.