Skip to content

Security and privacy

Your data stays yours. You control access.

You're trusting Apex with purchase history, product costs, customer events, and analytics. We keep each workspace separate, encrypt data in transit and at rest, enforce the consent signals you provide, and let you decide which connected systems can receive personal data.

No credit card to start.

Your workspace boundaryProtected

Data you choose to connect

  • Purchase history
  • Product costs
  • Customer events
  • Analytics
ApexYour Apex workspacePerson, workspace, and permission must all match.
Another workspace can’t use its session or API key to read yours.

Workspace isolation

Every request has to prove where it belongs.

Choosing a workspace in the browser doesn’t grant access. Apex checks the signed-in person or API key against that workspace before it reads or changes protected data.

Workspace access check

Incoming request

Owner signed inYour workspace
  1. IdentityVerified
  2. Workspace membershipMatched
  3. Required roleAllowed
Request allowedOnly the requested workspace data is returned.

Encryption and secret handling

Encrypted in transit. Encrypted at rest.

TLS 1.2+ encrypts data as it moves. Workspace data, backups, and connection credentials stay encrypted while stored. Before Apex writes a log, it removes known personal-data and secret fields.

In transit

TLS 1.2+Traffic is encrypted between your systems, the browser, and Apex.

At rest

Encrypted storageStored workspace data and backups are encrypted.

Credentials

Encrypted separatelyConnection secrets don't appear in API responses.

Operational logs

Sensitive fields redactedApex removes known personal-data and secret fields before it writes logs.

You decide where data goes

Nothing leaves unless you allow it.

Connected platforms get only the data and actions you enable. Apex enforces the consent signals you provide before sending personal data. Industry benchmarking stays off unless you opt into the Data Co-op.

Data controlsCurrent defaults
  • Connected platformsOff until you connect them

    A platform gets data only after you authorize the connection.

  • Outbound personal dataConsent checked before sending

    Apex follows the consent signals supplied by your consent manager.

  • Data Co-op benchmarkingOff by default

    Apex doesn't use your data for cross-customer benchmarks unless you opt in.

  • Customer privacy requestsRedaction supported

    Redact an individual customer's personal data when they ask.

Apex doesn’t sell your data. Industry benchmarking stays off unless you opt into the Data Co-op.

What you can verify

The controls are already in place.

Every workspace gets the same access checks, encryption, and recovery controls. You can review the public DPA and sub-processor registry before you connect data.

Built in todayControls you can verify6 in place
  • Every request is checked against its workspace
  • Owner, Admin, and Member access
  • TLS 1.2+ in transit and encryption at rest
  • Point-in-time database recovery
  • Backups expire on a rolling schedule, typically within 35 days
  • Public DPA and sub-processor registry
These controls cover every workspace. The DPA and sub-processor registry put them in writing.

Evidence and disclosure

Read the terms. Ask the hard questions.

Integration providers process data only after you connect them. Our public registry names each sub-processor, what it does, and where it operates.

security@apex.inc

Security disclosures, vendor reviews, and questionnaires.

Your move

Protect the data that explains your business.

Connect only what you need. Add access when you're ready. If your security review needs a human answer, write security@apex.inc.