Our Security Architecture

A transparent look at how Aevum News protects reader data, secures our infrastructure, and maintains the integrity of every story we publish.

All Systems Operational
๐Ÿ”’ SOC 2 Type II Certified
๐Ÿ›ก๏ธ ISO 27001 Compliant
โœ“ GDPR Ready
๐Ÿ”

Encryption Standard

AES-256 encryption for all data at rest and TLS 1.3 for data in transit

AES-256
๐ŸŒ

Global Infrastructure

Distributed across 12 availability zones in 6 geographic regions

12 AZs
๐Ÿ‘๏ธ

Threat Monitoring

24/7 automated threat detection with sub-second incident response

99.99%
๐Ÿ›ก๏ธ

Uptime SLA

Enterprise-grade reliability with redundant systems everywhere

99.99%

Defense in Depth

Our multi-layered security architecture ensures protection at every level of the stack.

๐ŸŒ

Edge / Perimeter Layer

DDoS mitigation, Web Application Firewall (WAF), rate limiting, and geographic access controls at the network edge.

Cloudflare AWS Shield GeoIP Filtering DDoS Protection
โ–ผ
โšก

API Gateway & Load Balancing

Authenticated API endpoints with mTLS, request signing, OAuth 2.0 / OIDC, and automated scaling load balancers.

Kong API Gateway mTLS OAuth 2.0 ALB/NLB
โ–ผ
๐Ÿ”ง

Application Services Layer

Microservices architecture with zero-trust networking, secrets management, runtime security scanning, and service mesh.

Kubernetes Istio Service Mesh Vault Secrets Runtime Protection
โ–ผ
๐Ÿ’พ

Data & Storage Layer

Encrypted databases, immutable audit logs, tokenized PII, geo-replicated storage with automated backup and recovery.

PostgreSQL (Encrypted) Redis (At Rest) S3 (KMS) WORM Storage
โ–ผ
๐Ÿ‘๏ธ

Observability & Security Monitoring

Centralized logging, SIEM integration, anomaly detection, automated alerting, and full chain-of-custody audit trails.

Splunk SIEM Datadog Prometheus Grafana Falco

Security Pillars

The core principles that drive our security strategy.

๐Ÿ”‘

Identity & Access Management

Zero-trust identity framework with multi-factor authentication, role-based access control (RBAC), and just-in-time privileged access.

  • โœ“ Multi-factor authentication (FIDO2 / TOTP) for all user accounts
  • โœ“ RBAC with principle of least privilege across all systems
  • โœ“ Just-in-time (JIT) privileged access with automatic expiry
  • โœ“ SSO integration via SAML 2.0 and OIDC for enterprise clients
  • โœ“ Session management with sliding expiry and anomaly detection
  • โœ“ Service-to-service authentication via mutual TLS certificates
๐Ÿ”’

Data Protection & Encryption

End-to-end encryption with hardware security module (HSM) backed key management and tokenization of sensitive personal data.

  • โœ“ AES-256-GCM encryption for all data at rest
  • โœ“ TLS 1.3 for all data in transit โ€” no legacy protocol support
  • โœ“ AWS CloudHSM for cryptographic key management (FIPS 140-2 L3)
  • โœ“ PII tokenization for payment and subscriber data
  • โœ“ Client-side encryption for journalist source protection
  • โœ“ Automated key rotation every 90 days with audit logging
๐ŸŒ

Network Security

Segmented micro-services network with zero-trust architecture, preventing lateral movement and containing any potential breach.

  • โœ“ VPC peering with security groups and NACLs
  • โœ“ Service mesh (Istio) for mTLS between all microservices
  • โœ“ Private endpoints for all database connections
  • โœ“ Bastion hosts for administrative access โ€” no direct SSH
  • โœ“ DNS filtering and threat intelligence feeds
  • โœ“ Outbound traffic whitelisting per service
๐Ÿงช

Vulnerability Management

Continuous security testing with automated scanning, regular penetration tests, and a structured vulnerability disclosure program.

  • โœ“ SAST/DAST scanning in CI/CD pipeline โ€” blocks deployments
  • โœ“ Quarterly third-party penetration tests
  • โœ“ Container image scanning (Trivy + Snyk) before deployment
  • โœ“ Dependency vulnerability monitoring with auto-pr alerts
  • โœ“ Responsible disclosure program with bug bounty
  • โœ“ OSINT monitoring for credential leaks and exposure

Meeting the Standard

Aevum News adheres to the most rigorous industry compliance frameworks and data protection regulations.

Certified

SOC 2 Type II

AICPA Trust Services Criteria

Annually audited for security, availability, processing integrity, confidentiality, and privacy controls.

Certified

ISO 27001:2022

International Organization for Standardization

Certified Information Security Management System (ISMS) with continuous improvement cycle.

Compliant

GDPR

General Data Protection Regulation (EU)

Full data subject rights support, data processing agreements, and EU-based data residency options.

Compliant

CCPA / CPRA

California Consumer Privacy Act

Complete transparency and control for California residents including opt-out of data sale rights.

Certified

ISO 22301

Business Continuity Management

Certified business continuity and disaster recovery capabilities tested quarterly.

In Progress

ISO 27701

Privacy Information Management

Extension to ISO 27001 for privacy management systems โ€” certification expected Q3 2025.

Under the Hood

The concrete technologies and protocols powering our security stack.

๐Ÿ” Cryptography & Key Management

At-Rest EncryptionAES-256-GCM
In-Transit EncryptionTLS 1.3
Key ManagementAWS CloudHSM
FIPS Compliance140-2 Level 3
Key RotationEvery 90 days
HashingArgon2id / SHA-3

โ˜๏ธ Infrastructure & Hosting

Primary CloudAWS (us-east, eu-west)
OrchestrationKubernetes (EKS)
CDNCloudflare + CloudFront
Service MeshIstio (mTLS)
Container Runtimecontainerd + gVisor
IaCTerraform (reviewed)

๐Ÿ›ก๏ธ Application Security

WAFCloudflare WAF + AWS WAF
SASTSonarQube + Semgrep
DASTOWASP ZAP + Burp Pro
SCASnyk + Dependabot
Secret ScanningGitLeaks + TruffleHog
Runtime ProtectionFalco + Sysdig

๐Ÿ“Š Monitoring & Response

SIEMSplunk Enterprise
MetricsDatadog + Prometheus
Log AggregationELK Stack (WORM)
Incident MgmtPagerDuty + Xpand
MTTD Target< 30 seconds
MTTR Target< 15 minutes

Our Response Protocol

A structured, tested incident response process that ensures rapid containment and transparent communication.

Phase 1 โ€” Detection & Triage

Automated Alert & Initial Assessment

SIEM correlation rules, anomaly detection, and automated scanning identify potential security events. Security operations team triages and classifies severity within minutes.

Target: < 30 seconds
Phase 2 โ€” Containment

Isolate & Limit Blast Radius

Automated containment actions trigger: affected services are isolated via service mesh, compromised credentials are revoked, and network segments are quarantined. Manual verification follows immediately.

Target: < 5 minutes
Phase 3 โ€” Investigation

Forensic Analysis & Root Cause

Dedicated incident response team performs deep forensic analysis using immutable logs. Chain of custody is maintained for all evidence. Root cause and scope are determined.

Target: < 2 hours
Phase 4 โ€” Eradication & Recovery

Remove Threat & Restore Services

Threat actors are removed, vulnerabilities are patched, and services are gradually restored using verified clean images. Health checks and canary deployments ensure stability.

Target: < 4 hours
Phase 5 โ€” Communication

Stakeholder Notification

Affected users are notified within 72 hours per regulatory requirements. Internal stakeholders receive detailed briefings. Status page is updated in real-time throughout.

Target: < 72 hours
Phase 6 โ€” Post-Incident Review

Lessons Learned & Improvement

Blameless post-mortem conducted within one week. Findings feed into security backlog. Detection rules, playbooks, and infrastructure are updated to prevent recurrence.

Target: Within 7 days

Current Security Posture

Infrastructure
Operational
API Services
Operational
CDN / Edge
Operational
Database
Operational
Auth Service
Operational
Last Pen Test
14 days ago