01 Source & Journalist Protection
Protecting whistleblowers, anonymous sources, and field journalists is foundational to our editorial mission. We implement encrypted communication channels and strict operational security (OPSEC) protocols to prevent identification or retaliation.
- End-to-end encrypted messaging via Signal and Session for all source communications
- Dedicated secure drop infrastructure using SecureDrop and Tails OS workstations
- Metadata scrubbing protocols for all submitted documents, photos, and recordings
- Regular OPSEC training for editorial and field teams
02 Data Encryption & Secure Infrastructure
All sensitive data at rest and in transit is protected using AES-256 encryption and TLS 1.3 protocols. Our infrastructure is distributed across geographically isolated servers to prevent single-point failures or unauthorized access.
🔐 At-Rest Encryption
Database volumes, backups, and archival storage utilize AES-256 with hardware-backed key management.
🌐 In-Transit Security
All user traffic and internal API communications are enforced over TLS 1.3 with HSTS enabled.
🏢 Isolated Workstations
Editorial and legal teams operate on air-gapped or VPN-isolated machines for handling classified materials.
03 Access Control & Authentication
Access to internal systems follows the principle of least privilege. Multi-factor authentication (MFA) is mandatory for all staff, contractors, and third-party integrations. Role-based access control (RBAC) ensures journalists only access materials relevant to their assignments.
- Hardware-backed MFA (YubiKey/TOTP) for all administrative and editorial accounts
- Time-bound session tokens with automatic logout after inactivity
- Regular access audits and privilege reviews conducted quarterly
- Immutable audit logging for all document access and data exports
04 Compliance & Data Privacy Standards
Aevum News adheres to international data protection regulations including GDPR, CCPA, and local press freedom laws. We maintain a Data Protection Officer (DPO) and conduct annual third-party compliance audits.
- Privacy-by-design architecture across all digital platforms
- Minimal data collection policy — no behavioral tracking or fingerprinting
- Clear user consent mechanisms and easy data deletion workflows
- Cross-border data transfer safeguards and local storage where mandated
05 Incident Response & Cyber Resilience
In the event of a security breach or cyber incident, Aevum News activates a predefined incident response plan within 60 minutes. Our team maintains regular communication channels with independent cybersecurity firms and legal counsel.
- 24/7 Security Operations Center (SOC) monitoring with automated threat detection
- Quarterly penetration testing and red-team exercises
- Offsite, encrypted, and version-controlled backups with 30-day retention
- Public disclosure protocol for confirmed breaches affecting user or source data