Enterprise security, independently validated.
Aptori protects customer data and enterprise environments through independent assurance, encryption, access controls, secure development, continuous monitoring, and third-party security testing.
Protect data in transit and at rest.
Encryption and controlled access help protect sensitive customer and platform data.
Control who can access what.
SSO, role-based access controls, and defined responsibilities support least-privilege access.
Validate security independently.
SOC 2 Type II controls and third-party security assessments provide external assurance.
Monitor and respond.
Security monitoring, alerting, and defined response processes help identify and address security events.
Independent assurance over Aptori security controls.
Aptori has completed a SOC 2 Type II examination covering relevant security controls. For enterprise evaluations, our team can discuss available security and compliance documentation under the appropriate confidentiality process.
Protect customer data, control access, and continuously validate security.
Protect customer data.
Use industry-standard encryption to protect sensitive data in transit and at rest.
Control access.
Use SSO, role-based access control, and defined permissions to restrict access based on responsibility.
Secure the environment.
Use cloud and platform security controls, segmentation, hardened configurations, and operational safeguards.
Detect security events.
Monitor systems and security signals for anomalous activity, configuration changes, and access events.
Security is built into how we develop Aptori.
Aptori continuously tests its software, APIs, dependencies, infrastructure, and deployment configurations throughout development and release.
Test software before release.
Use code analysis, dependency security, secrets detection, and software composition controls in development workflows.
Validate application behavior.
Test application and API security, including authentication, authorization, and runtime behavior.
Validate deployment security.
Assess containers, infrastructure-as-code, Kubernetes, and cloud configuration as software moves toward production.
Challenge our controls independently.
Use external security specialists and penetration testing to identify weaknesses and validate security improvements.
Train employees continuously.
Require security awareness and role-appropriate training covering secure development, phishing, credentials, and data protection.
Define ownership and accountability.
Maintain documented security responsibilities, policies, control ownership, and review processes across the organization.
Protect sensitive information throughout its lifecycle.
Aptori protects customer data with encryption, access controls, data minimization, secure handling, and documented retention practices.
Collect what is needed.
Limit collection and processing to information required to provide and operate Aptori services.
Restrict sensitive data access.
Limit access based on role, responsibility, and business need.
Protect customer information.
Use contractual, organizational, and technical safeguards to protect confidential information.
Manage data over time.
Apply documented handling and retention practices appropriate to customer and operational requirements.
Deploy Aptori where your applications and data need to stay.
Choose the deployment model that meets your security, data residency, sovereignty, and operational requirements.
Fully managed deployment
Use Aptori as a managed service with enterprise security and operational safeguards.
Dedicated infrastructure
Run Aptori in a dedicated environment for organizations with stronger isolation requirements.
Your cloud or data center
Deploy Aptori within your cloud, Kubernetes, or on-premises environment.
Sovereign and air-gapped
Keep applications, source code, security data, and AI processing within your controlled environment.
Found a possible security vulnerability?
We appreciate responsible reports from security researchers and customers. Please provide enough detail for our security team to reproduce and evaluate the issue.
Report a security concern.
Include the affected Aptori service or component, a clear description of the issue, reproduction steps, and any supporting evidence that can help us investigate.
Aptori Security Center.
Is Aptori SOC 2 Type II compliant?
Yes. Aptori has completed a SOC 2 Type II examination covering relevant security controls. Enterprise customers can discuss available assurance documentation with Aptori during the security-review process.
How does Aptori protect customer data?
Aptori uses encryption, access controls, secure development practices, monitoring, employee security training, and third-party security testing to protect customer data and systems.
Does Aptori support SSO and role-based access control?
Yes. Aptori supports enterprise identity and access controls including SSO and role-based permissions for supported deployments.
Does Aptori perform penetration testing?
Aptori uses third-party security testing and penetration testing as part of its security program to identify weaknesses and validate security improvements.
Can Aptori be deployed in private or restricted environments?
Aptori supports enterprise deployment options including managed, dedicated, customer-hosted, sovereign, and air-gapped environments to meet different security and deployment requirements.
