Launching August 2026 Apply for beta access →
APEX

trust & security

The evidence collects itself.

What you put into APEX is your real work, not a sandbox, so we built it to look after that work from the first signup to the day you ask it to be gone. Your security team will be fine. The proof is already in the product.

See it on your own data

the short version

Built so the answers are already there.

When someone asks how your data is handled, you forward a link instead of starting a project.

Your tenant stays yours

Every row carries a tenant_id, and Postgres FORCE row-level security binds each request to its tenant. The database returns only your rows, by design.

Encrypted coming and going

AES-256 at rest, TLS 1.2+ in transit. Customer secrets are encrypted at rest and never stored in plaintext.

The audit trail writes itself

Every mutating action records who, when, the IP, and what changed, to an append-only log. You do not have to remember to turn it on.

how a workspace lives

From signup to deletion, with no surprises.

Every account starts the same way: 30 days free, no sales call. What you use on day one is what you keep if you convert.

01

Signup

Your tenant is created and a wizard sets up company, location, project, and teammates.

02

Active trial

Full feature access for 30 days. Friendly reminders at day 25 and 28, never a cold cutoff.

03

Grace period

Read-only and preserved through day 60. Pick any path to restore write access instantly.

04

Clean exit

If you walk away, data is wiped at day 90 and encrypted backups rotate out by day 120.

Convert before day 90 and the workspace is yours to keep as a paid tenant, with the same protections and no expiry.

what protects it

The protections, in plain terms.

Real controls, already on. Nothing here is a future promise unless we say so.

Per-tenant isolation

Postgres FORCE row-level security binds each request to its tenant, and the requireTenant middleware sets that boundary on every call. You get only your rows.

Nine-role RBAC, RS256 JWT

Access is scoped by a nine-role RBAC model, with sessions signed using RS256 JWT. People see exactly what their role allows, nothing more.

Only your invited users

APEX engineering has no routine access to tenant data. Support sessions require your explicit consent and are logged. Third parties get access only when you grant it.

US data centers

All customer data lives in US-based data centers at launch. EU / UK residency is on the roadmap. If it's a blocker for you today, talk to us.

Zero trackers in the app

No GA, no Pixel, no LinkedIn, no Twitter, no session-replay. The signed-in app at /app ships no third-party scripts. Marketing pages use privacy-respecting analytics only.

Append-only audit log

Every mutating action lands in an append-only log with who, when, the IP, and what they did, with one-click CSV export for your SIEM. Full before/after value diffs are coming soon.

your rights, your buttons

You stay in control of your data.

Export it, delete it, or see who touched it, on your schedule, not ours.

Things you can do today

Yours to act on
Right to know. See who in your tenant accessed what, and when, from the Audit log view.
Right to deletion. Request permanent deletion any time from Settings, Delete Workspace. Typically within 7 days for trial workspaces and 30 days for paid, in line with common GDPR / CCPA windows.
Consent on integrations. No third party touches your tenant without your explicit grant, and support sessions run through your consent flow.
Right to export. Workspace, projects, users, partners, field ops, and locations as structured JSON from Administration, Export Workspace. Audit log exports as CSV.

Landing soon

On the way
Full before/after value diffs in the audit trail
EU / UK data residency options

who helps run it

A short, honest subprocessor list.

We update this whenever a subprocessor changes. Paid plans can subscribe to those notifications by email.

Cloudflare

CDN, WAF, edge DNS. US POPs in the routing path.

PostgreSQL

Self-hosted, US data center. The primary application database.

Object storage

S3-compatible, US region, for attachments and documents (coming soon). Attachments sit on encrypted local disk today.

Email provider

Sends invite, password reset, and trial reminder email. Does not store customer workspace data.

when you connect a cloud

Integrations only see what you hand them.

Plugins like Cisco Control Hub and Microsoft Graph / Teams Rooms ask first, every time.

Consent before any call

Plugins require explicit per-tenant OAuth consent before any external call happens. You see the scopes before you grant them.

Every call is logged

Each external API call lands in your audit trail with timestamp, endpoint, response code, and the user who initiated it.

Yours to revoke

We only pull from clouds you connect, and your manufacturer-cloud data stays inside your tenant. Revoke from Settings, Integrations, Disconnect.

Have a question we did not answer?

Email [email protected] on data handling, deletion, export, or compliance. For a specific legal review (SOC 2, GDPR DPA, custom MSA), email us and we'll walk through it.

Start your 30 days free