Our Security Foundation

Every system, process, and policy at Aevum News is designed around five non-negotiable security pillars.

🔐

Zero-Trust Architecture

No user, device, or network segment is inherently trusted. Continuous verification and least-privilege access govern all operations.

🛡️

Encryption at Rest & Transit

All data is encrypted using AES-256-GCM for storage and TLS 1.3 for transmission. Keys are managed via hardware-backed HSMs.

📊

Data Minimization

We collect only what is strictly necessary. Personal identifiers are pseudonymized where possible and excluded from analytics logs.

🔍

Continuous Monitoring

24/7 SIEM-driven threat detection, automated anomaly response, and quarterly penetration testing ensure rapid incident mitigation.

Technical Safeguards

Our security stack is built for resilience, auditability, and strict access governance.

01

Network Segmentation & WAF

Micro-segmented VPCs, DDoS mitigation, and Next-Gen WAF rules block malicious traffic before it reaches application layers.

02

Identity & Access Management

RBAC + ABAC policies, MFA enforcement, and session token rotation. Source code access requires hardware security keys.

03

Secure Development Lifecycle

Static/dynamic analysis, SAST/DAST pipelines, and dependency scanning prevent vulnerabilities from entering production.

04

Immutable Backups & DR

WORM-compliant backups, geo-redundant storage, and automated failover ensure RPO < 15min, RTO < 1hr.

Compliance & Certifications

Aevum News maintains full alignment with global data protection frameworks and undergoes independent third-party audits annually.

GDPR Compliant
CCPA/CPRA Aligned
SOC 2 Type II
ISO 27001 Certified
NIST CSF 2.0
FERPA (Editorial Data)

Data Retention & Deletion

  • Account logs: 90 days (anonymized after 30)
  • Newsletter subscriptions: Indefinite (opt-out anytime)
  • Comment & feedback data: 2 years or upon request
  • Internal editorial drafts: 5 years (archived & encrypted)
  • All deletion requests processed within 30 days

Access & Source Protection

  • Journosimistic sources protected via PGP & secure drop portals
  • Internal data access requires dual-authorization & audit logging
  • Third-party integrations limited to SOC 2-compliant vendors
  • Employee background checks & security training required
  • Legal subpoenas reviewed by independent counsel before response

Privacy Controls & User Rights

You retain full ownership of your data. Exercise your rights transparently through our self-service portal.

Right to Access

Request a complete export of your personal data in JSON/CSV format via Account Settings → Privacy.

Right to Erasure

Permanently delete your account and associated metadata. Editorial comments are anonymized upon request.

Right to Restrict Processing

Pause data collection for analytics & personalization without affecting core service functionality.

Cookie & Tracker Management

Granular controls for first-party, third-party, and advertising cookies. Do-Not-Track respected.

Security Incident Response

In the event of a security event, Aevum News follows a structured, transparent response framework.

Detection & Containment (0–1hr)

Automated alerts trigger isolation of affected systems. Network segmentation prevents lateral movement.

Forensic Analysis (1–24hrs)

Internal IR team & external CIRT partners conduct log analysis, malware triage, and scope assessment.

Notification & Remediation (24–72hrs)

Regulators & affected users are notified per legal timelines. Patches, key rotations, & system hardening are deployed.

Post-Incident Review (7–14 days)

Transparent report published on our Trust Center. Lessons integrated into architecture & policy updates.

Security & Privacy Inquiries

Absolutely not. Aevum News does not sell, lease, or trade personal data. Revenue is generated exclusively through subscriptions, editorial partnerships, and non-intrusive programmatic advertising that respects cookie consent.
We operate encrypted drop portals, PGP key management, and metadata stripping for all incoming submissions. Internal routing uses air-gapped editorial channels. We do not retain identifiable contact metadata for protected sources.
All legal demands are reviewed by independent counsel. We only disclose the minimum required by law, publish transparency reports quarterly, and advocate for editorial privilege where legally permissible.
Yes. Navigate to Account → Privacy → Data Management. Exports are generated within 48 hours. Deletion requests are processed within 30 days, with editorial content anonymized per our policy.

Security Contact

Found a security issue or have questions about our privacy practices? Reach our Data Protection Officer directly.

security@aevumnews.com

PGP Key: 0xA8E2 9F14 7C3D 6B89 | Response within 48 hours