Security and privacy
Your data stays yours. You control access.
You're trusting Apex with purchase history, product costs, customer events, and analytics. We keep each workspace separate, encrypt data in transit and at rest, enforce the consent signals you provide, and let you decide which connected systems can receive personal data.
No credit card to start.
Data you choose to connect
- Purchase history
- Product costs
- Customer events
- Analytics
Workspace isolation
Every request has to prove where it belongs.
Choosing a workspace in the browser doesn’t grant access. Apex checks the signed-in person or API key against that workspace before it reads or changes protected data.
Incoming request
Owner signed inYour workspace- IdentityVerified
- Workspace membershipMatched
- Required roleAllowed
Encryption and secret handling
Encrypted in transit. Encrypted at rest.
TLS 1.2+ encrypts data as it moves. Workspace data, backups, and connection credentials stay encrypted while stored. Before Apex writes a log, it removes known personal-data and secret fields.
In transit
TLS 1.2+Traffic is encrypted between your systems, the browser, and Apex.At rest
Encrypted storageStored workspace data and backups are encrypted.Credentials
Encrypted separatelyConnection secrets don't appear in API responses.Operational logs
Sensitive fields redactedApex removes known personal-data and secret fields before it writes logs.You decide where data goes
Nothing leaves unless you allow it.
Connected platforms get only the data and actions you enable. Apex enforces the consent signals you provide before sending personal data. Industry benchmarking stays off unless you opt into the Data Co-op.
- Connected platformsOff until you connect them
A platform gets data only after you authorize the connection.
- Outbound personal dataConsent checked before sending
Apex follows the consent signals supplied by your consent manager.
- Data Co-op benchmarkingOff by default
Apex doesn't use your data for cross-customer benchmarks unless you opt in.
- Customer privacy requestsRedaction supported
Redact an individual customer's personal data when they ask.
What you can verify
The controls are already in place.
Every workspace gets the same access checks, encryption, and recovery controls. You can review the public DPA and sub-processor registry before you connect data.
- Every request is checked against its workspace
- Owner, Admin, and Member access
- TLS 1.2+ in transit and encryption at rest
- Point-in-time database recovery
- Backups expire on a rolling schedule, typically within 35 days
- Public DPA and sub-processor registry
Evidence and disclosure
Read the terms. Ask the hard questions.
Integration providers process data only after you connect them. Our public registry names each sub-processor, what it does, and where it operates.
security@apex.incSecurity disclosures, vendor reviews, and questionnaires.
Your move
Protect the data that explains your business.
Connect only what you need. Add access when you're ready. If your security review needs a human answer, write security@apex.inc.