APTOrI SECURITY CENTER

Enterprise security, independently validated.

Aptori protects customer data and enterprise environments through independent assurance, encryption, access controls, secure development, continuous monitoring, and third-party security testing.

SOC 2 Type IIEncryptionSSO + RBACThird-party testingEnterprise deployment
How Aptori protects your environmentPROTECT → MONITOR → VALIDATE → IMPROVE
DATA PROTECTION

Protect data in transit and at rest.

Encryption and controlled access help protect sensitive customer and platform data.

ACCESS

Control who can access what.

SSO, role-based access controls, and defined responsibilities support least-privilege access.

ASSURANCE

Validate security independently.

SOC 2 Type II controls and third-party security assessments provide external assurance.

OPERATIONS

Monitor and respond.

Security monitoring, alerting, and defined response processes help identify and address security events.

SECURITY CONTROLS → INDEPENDENT ASSURANCE → CONTINUOUS IMPROVEMENT
SOC 2 TYPE II

Independent assurance over Aptori security controls.

Aptori has completed a SOC 2 Type II examination covering relevant security controls. For enterprise evaluations, our team can discuss available security and compliance documentation under the appropriate confidentiality process.

SECURITYSecurity controlsPolicies, responsibilities, access controls, operational processes, and monitoring.
ACCESSIdentity and access managementAuthentication, SSO, RBAC, and least-privilege administrative access.
OPERATIONSMonitoring and responseSecurity monitoring, alerting, incident processes, and control review.
ASSURANCEIndependent examinationThird-party evaluation of the design and operating effectiveness of relevant controls over the review period.
CORE SECURITY PRACTICES

Protect customer data, control access, and continuously validate security.

ENCRYPTION

Protect customer data.

Use industry-standard encryption to protect sensitive data in transit and at rest.

IDENTITY

Control access.

Use SSO, role-based access control, and defined permissions to restrict access based on responsibility.

INFRASTRUCTURE

Secure the environment.

Use cloud and platform security controls, segmentation, hardened configurations, and operational safeguards.

MONITORING

Detect security events.

Monitor systems and security signals for anomalous activity, configuration changes, and access events.

SECURE DEVELOPMENT

Security is built into how we develop Aptori.

Aptori continuously tests its software, APIs, dependencies, infrastructure, and deployment configurations throughout development and release.

SOFTWARE SECURITY

Test software before release.

Use code analysis, dependency security, secrets detection, and software composition controls in development workflows.

APPLICATION & API SECURITY

Validate application behavior.

Test application and API security, including authentication, authorization, and runtime behavior.

INFRASTRUCTURE

Validate deployment security.

Assess containers, infrastructure-as-code, Kubernetes, and cloud configuration as software moves toward production.

INDEPENDENT SECURITY TESTING

Challenge our controls independently.

Use external security specialists and penetration testing to identify weaknesses and validate security improvements.

SECURITY TRAINING

Train employees continuously.

Require security awareness and role-appropriate training covering secure development, phishing, credentials, and data protection.

SECURITY GOVERNANCE

Define ownership and accountability.

Maintain documented security responsibilities, policies, control ownership, and review processes across the organization.

DATA + PRIVACY

Protect sensitive information throughout its lifecycle.

Aptori protects customer data with encryption, access controls, data minimization, secure handling, and documented retention practices.

MINIMIZATION

Collect what is needed.

Limit collection and processing to information required to provide and operate Aptori services.

ACCESS

Restrict sensitive data access.

Limit access based on role, responsibility, and business need.

CONFIDENTIALITY

Protect customer information.

Use contractual, organizational, and technical safeguards to protect confidential information.

RETENTION

Manage data over time.

Apply documented handling and retention practices appropriate to customer and operational requirements.

ENTERPRISE DEPLOYMENT

Deploy Aptori where your applications and data need to stay.

Choose the deployment model that meets your security, data residency, sovereignty, and operational requirements.

APTOrI CLOUD

Fully managed deployment

Use Aptori as a managed service with enterprise security and operational safeguards.

DEDICATED ENVIRONMENT

Dedicated infrastructure

Run Aptori in a dedicated environment for organizations with stronger isolation requirements.

YOUR ENVIRONMENT

Your cloud or data center

Deploy Aptori within your cloud, Kubernetes, or on-premises environment.

SOVEREIGN

Sovereign and air-gapped

Keep applications, source code, security data, and AI processing within your controlled environment.

Explore Sovereign AI →

RESPONSIBLE DISCLOSURE

Found a possible security vulnerability?

We appreciate responsible reports from security researchers and customers. Please provide enough detail for our security team to reproduce and evaluate the issue.

SECURITY REPORTING

Report a security concern.

Include the affected Aptori service or component, a clear description of the issue, reproduction steps, and any supporting evidence that can help us investigate.

Contact Aptori Security →

FAQ

Aptori Security Center.

Is Aptori SOC 2 Type II compliant?

Yes. Aptori has completed a SOC 2 Type II examination covering relevant security controls. Enterprise customers can discuss available assurance documentation with Aptori during the security-review process.

How does Aptori protect customer data?

Aptori uses encryption, access controls, secure development practices, monitoring, employee security training, and third-party security testing to protect customer data and systems.

Does Aptori support SSO and role-based access control?

Yes. Aptori supports enterprise identity and access controls including SSO and role-based permissions for supported deployments.

Does Aptori perform penetration testing?

Aptori uses third-party security testing and penetration testing as part of its security program to identify weaknesses and validate security improvements.

Can Aptori be deployed in private or restricted environments?

Aptori supports enterprise deployment options including managed, dedicated, customer-hosted, sovereign, and air-gapped environments to meet different security and deployment requirements.

ENTERPRISE SECURITY REVIEW

Evaluate Aptori security, deployment, and assurance with our team.

Talk to Aptori ↗