Security Pillars

Every aspect of our operation is engineered to protect information, people, and truth.

🛡️

Data Privacy & Retention

We minimize data collection and encrypt everything at rest and in transit.

  • AES-256 encryption for all stored data
  • Zero-knowledge architecture for user accounts
  • Automatic data purging after 180 days of inactivity
  • Strict GDPR, CCPA & PECR compliance
📁

Source & Whistleblower Protection

Anonymity is guaranteed through verified secure channels.

  • SecureDrop instance with hardware isolation
  • Mandatory PGP key verification
  • No metadata logging or IP tracking
  • Editorial firewall separating sources from legal/comms
✍️

Editorial & Content Security

Stories are protected from tampering, bias injection, and unauthorized edits.

  • Multi-signature approval workflow
  • Immutable publication logging (WORM storage)
  • Real-time plagiarism & AI-content detection
  • Strict separation of ad tech from editorial stack
🌐

Infrastructure & Network

Enterprise-grade defenses ensuring uninterrupted, secure access.

  • Zero-trust network architecture
  • DDoS mitigation via distributed edge nodes
  • Bi-weekly penetration testing by third parties
  • Hardware security keys for all staff access

Submit Information Securely

If you have evidence, documents, or insights for our journalists, use our encrypted submission portal. All materials are stored on air-gapped systems and reviewed only by designated editors.

PGP-Encrypted Email Signal / Session SecureDrop Web Portal Dead Drop (Physical)
🔐 Access Secure Submission →

Incident Response Protocol

Standardized procedures activated immediately upon detecting a security event.

1

Detection & Triage

Automated SIEM alerts trigger immediate isolation of affected systems. Security team verifies scope within 15 minutes.

2

Containment

Network segmentation, credential rotation, and traffic rerouting. Backup systems activated if compromised.

3

Investigation

Forensic imaging, log analysis, and third-party auditor engagement. Root cause documented in encrypted vault.

4

Disclosure & Recovery

Transparent public statement within 72 hours. Post-incident review published quarterly. Systems fully restored.

Compliance & Audits

Third-party verified. Regularly updated. Publicly accountable.

Framework / Standard Status Last Audit Next Review
GDPR & EU Data Protection Compliant Q3 2024 Q3 2025
ISO 27001 Information Security Certified Q4 2024 Q4 2025
SOC 2 Type II (Privacy & Security) Verified Q2 2024 Q2 2025
OWASP Application Security Under Review Q1 2025 Q3 2025
Editorial Integrity Charter (SPJ) Adhered Annual Annual

Report a Vulnerability

Responsible disclosure is rewarded. All reports are handled confidentially by our CISO team.

📧

Security Team Contact

For vulnerability reports, security inquiries, or audit requests:

  • Email: security@aevumnews.com
  • PGP Key: 0xDEADBEEF4C8A1922
  • Bug Bounty: Up to $15,000 for critical findings
  • Response Time: Within 24 hours