πŸ›‘οΈ Verified & Encrypted

Security & Trust

We protect our journalists, our sources, and our readers. Every layer of Aevum News is engineered for resilience, privacy, and transparency.

How We Protect What Matters

Security isn't a featureβ€”it's our foundation. Every system, process, and policy is designed around trust.

πŸ”

End-to-End Encryption

All data in transit and at rest is encrypted using AES-256 and TLS 1.3. Source communications are protected with PGP and secure drop infrastructure.

Data Protection
🌐

Zero-Trust Architecture

No implicit trust, anywhere. Every access request is verified, authenticated, and authorized. Micro-segmentation isolates critical editorial systems.

Infrastructure
πŸ‘οΈ

Continuous Monitoring

24/7 threat detection, log analysis, and anomaly response. Our SOC operates around the clock to neutralize threats before they impact operations.

Operations
πŸ“„

Source Confidentiality

We maintain strict compartmentalization, encrypted storage, and minimal data retention policies to protect journalistic sources at all costs.

Journalism
⚑

Incident Response

Automated playbooks, rapid containment protocols, and transparent post-incident reporting. We prepare for breaches so we never suffer from them.

Resilience
πŸ”

Independent Audits

Annual penetration testing, code reviews, and third-party security assessments. We invite scrutiny to ensure our promises hold.

Verification

Report Vulnerabilities

We welcome responsible security researchers. Help us keep Aevum News secure.

1. Submit Report

Send detailed findings to our security team via encrypted channels. Include reproduction steps, impact, and affected endpoints.

2. Acknowledge & Triage

We respond within 24 hours. Valid reports are assigned a tracking ID and prioritized by severity (Critical, High, Medium, Low).

3. Remediation

Our engineering team patches vulnerabilities within agreed timelines. We keep reporters updated on progress.

4. Resolution & Recognition

Once fixed, we confirm closure and publicly acknowledge contributors in our security hall of fame (with permission).

Submission Guidelines

To ensure your report is handled properly, please follow these guidelines:

  • Do not exploit vulnerabilities beyond proof-of-concept
  • Do not access, modify, or delete user data
  • Do not use destructive scanning or DoS techniques
  • Provide clear, step-by-step reproduction instructions
  • Allow 90 days for resolution before public disclosure
PGP Public Key (Fingerprint: A3F1 8B92 C4D0 1E5F 7A29 0D8C 4B31 E6F9 2A7C 5D81)
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBF2k8xQBEADKp8vN2xJ9... (truncated)
-----END PGP PUBLIC KEY BLOCK-----
\n

Certified & Audited

We adhere to globally recognized security and privacy frameworks.

πŸ‡ͺπŸ‡Ί

GDPR Compliant

Full data protection alignment for EU readers. Explicit consent, right to erasure, and data portability enforced.

πŸ”’

ISO 27001:2022

Certified Information Security Management System. Regular surveillance audits ensure continuous compliance.

πŸ“Š

SOC 2 Type II

Independent verification of security, availability, processing integrity, confidentiality, and privacy controls.

πŸ‡ΊπŸ‡Έ

CCPA / CPRA Ready

California consumer privacy rights fully implemented. Opt-out mechanisms and data mapping actively maintained.

Security & Infrastructure Health

Real-time visibility into our critical systems and recent security events.

System / Component Status Last Incident Uptime (30d)
CDN & Edge Network Operational None 99.998%
Secure Drop Portal Operational 2024-11-12 99.999%
Editorial CMS Operational 2024-09-03 99.97%
Authentication Services Operational None 99.995%
Database Clusters Operational 2024-08-19 99.99%

Report an Issue

Have a concern or discovered a vulnerability? Use the form below or email security@aevumnews.com