Security Pillars
Every aspect of our operation is engineered to protect information, people, and truth.
Data Privacy & Retention
We minimize data collection and encrypt everything at rest and in transit.
- AES-256 encryption for all stored data
- Zero-knowledge architecture for user accounts
- Automatic data purging after 180 days of inactivity
- Strict GDPR, CCPA & PECR compliance
Source & Whistleblower Protection
Anonymity is guaranteed through verified secure channels.
- SecureDrop instance with hardware isolation
- Mandatory PGP key verification
- No metadata logging or IP tracking
- Editorial firewall separating sources from legal/comms
Editorial & Content Security
Stories are protected from tampering, bias injection, and unauthorized edits.
- Multi-signature approval workflow
- Immutable publication logging (WORM storage)
- Real-time plagiarism & AI-content detection
- Strict separation of ad tech from editorial stack
Infrastructure & Network
Enterprise-grade defenses ensuring uninterrupted, secure access.
- Zero-trust network architecture
- DDoS mitigation via distributed edge nodes
- Bi-weekly penetration testing by third parties
- Hardware security keys for all staff access
Submit Information Securely
If you have evidence, documents, or insights for our journalists, use our encrypted submission portal. All materials are stored on air-gapped systems and reviewed only by designated editors.
Incident Response Protocol
Standardized procedures activated immediately upon detecting a security event.
Detection & Triage
Automated SIEM alerts trigger immediate isolation of affected systems. Security team verifies scope within 15 minutes.
Containment
Network segmentation, credential rotation, and traffic rerouting. Backup systems activated if compromised.
Investigation
Forensic imaging, log analysis, and third-party auditor engagement. Root cause documented in encrypted vault.
Disclosure & Recovery
Transparent public statement within 72 hours. Post-incident review published quarterly. Systems fully restored.
Compliance & Audits
Third-party verified. Regularly updated. Publicly accountable.
| Framework / Standard | Status | Last Audit | Next Review |
|---|---|---|---|
| GDPR & EU Data Protection | Compliant | Q3 2024 | Q3 2025 |
| ISO 27001 Information Security | Certified | Q4 2024 | Q4 2025 |
| SOC 2 Type II (Privacy & Security) | Verified | Q2 2024 | Q2 2025 |
| OWASP Application Security | Under Review | Q1 2025 | Q3 2025 |
| Editorial Integrity Charter (SPJ) | Adhered | Annual | Annual |
Report a Vulnerability
Responsible disclosure is rewarded. All reports are handled confidentially by our CISO team.
Security Team Contact
For vulnerability reports, security inquiries, or audit requests:
- Email: security@aevumnews.com
- PGP Key:
0xDEADBEEF4C8A1922 - Bug Bounty: Up to $15,000 for critical findings
- Response Time: Within 24 hours