Our Security Foundation
Every system, process, and policy at Aevum News is designed around five non-negotiable security pillars.
Zero-Trust Architecture
No user, device, or network segment is inherently trusted. Continuous verification and least-privilege access govern all operations.
Encryption at Rest & Transit
All data is encrypted using AES-256-GCM for storage and TLS 1.3 for transmission. Keys are managed via hardware-backed HSMs.
Data Minimization
We collect only what is strictly necessary. Personal identifiers are pseudonymized where possible and excluded from analytics logs.
Continuous Monitoring
24/7 SIEM-driven threat detection, automated anomaly response, and quarterly penetration testing ensure rapid incident mitigation.
Technical Safeguards
Our security stack is built for resilience, auditability, and strict access governance.
Network Segmentation & WAF
Micro-segmented VPCs, DDoS mitigation, and Next-Gen WAF rules block malicious traffic before it reaches application layers.
Identity & Access Management
RBAC + ABAC policies, MFA enforcement, and session token rotation. Source code access requires hardware security keys.
Secure Development Lifecycle
Static/dynamic analysis, SAST/DAST pipelines, and dependency scanning prevent vulnerabilities from entering production.
Immutable Backups & DR
WORM-compliant backups, geo-redundant storage, and automated failover ensure RPO < 15min, RTO < 1hr.
Compliance & Certifications
Aevum News maintains full alignment with global data protection frameworks and undergoes independent third-party audits annually.
Data Retention & Deletion
- Account logs: 90 days (anonymized after 30)
- Newsletter subscriptions: Indefinite (opt-out anytime)
- Comment & feedback data: 2 years or upon request
- Internal editorial drafts: 5 years (archived & encrypted)
- All deletion requests processed within 30 days
Access & Source Protection
- Journosimistic sources protected via PGP & secure drop portals
- Internal data access requires dual-authorization & audit logging
- Third-party integrations limited to SOC 2-compliant vendors
- Employee background checks & security training required
- Legal subpoenas reviewed by independent counsel before response
Privacy Controls & User Rights
You retain full ownership of your data. Exercise your rights transparently through our self-service portal.
Right to Access
Request a complete export of your personal data in JSON/CSV format via Account Settings → Privacy.
Right to Erasure
Permanently delete your account and associated metadata. Editorial comments are anonymized upon request.
Right to Restrict Processing
Pause data collection for analytics & personalization without affecting core service functionality.
Cookie & Tracker Management
Granular controls for first-party, third-party, and advertising cookies. Do-Not-Track respected.
Security Incident Response
In the event of a security event, Aevum News follows a structured, transparent response framework.
Detection & Containment (0–1hr)
Automated alerts trigger isolation of affected systems. Network segmentation prevents lateral movement.
Forensic Analysis (1–24hrs)
Internal IR team & external CIRT partners conduct log analysis, malware triage, and scope assessment.
Notification & Remediation (24–72hrs)
Regulators & affected users are notified per legal timelines. Patches, key rotations, & system hardening are deployed.
Post-Incident Review (7–14 days)
Transparent report published on our Trust Center. Lessons integrated into architecture & policy updates.
Security & Privacy Inquiries
Security Contact
Found a security issue or have questions about our privacy practices? Reach our Data Protection Officer directly.
security@aevumnews.comPGP Key: 0xA8E2 9F14 7C3D 6B89 | Response within 48 hours