Skip to main content
Login
Apus Platform

Enterprise security & compliance.

Your data is yours — protected in depth, ready for the strictest requirements.

Enterprise security

Multi-layer security approach
Defense in depth across every system layer.
Encryption in transit (TLS)
TLS on the wire.
Access control & audit logs
Granular permissions; the audit-log scope is stated under Compliance below.
ISO 27001 (in certification) & GDPR compliance
ISO 27001 is in the certification process; GDPR is a compliance framework, not a certification.
The audit log covers AI actions too
Every agent run is logged: which agent, on whose delegation, whose data it read, and who approved.

Backup & recovery

Continuous backup
Data is backed up continuously, on the cycle committed in your contract.
Multi-site redundancy
On Dedicated Cloud: redundancy per your plan and the SLA appendix; when self-hosted: per the infrastructure you choose.
Recovery Time Objective (RTO)
Per your plan and the contract's SLA appendix.
Recovery Point Objective (RPO)
Bounded maximum data loss — per your plan and the SLA appendix.
Business Continuity Plan (BCP)
Keeps operations running through incidents.
SERVICE COMMITMENTS

Operational SLA — committed in the contract, not just in words.

The specific commitments — uptime, response times by incident severity, recovery objectives — live in the service contract and the SLA appendix of each support plan.

Operating model
Dedicated instance

Every customer runs its own instance — no application or database shared with another company. Availability follows your plan and your contract's SLA appendix — there is no single published uptime figure.

Incident classes
P1–P4

Incidents are classified by impact; each class has a target response time per support plan.

Recovery
RTO / RPO

Recovery time and recovery point objectives per your plan and the SLA appendix — backup mechanics are covered above.

The three support levels and the P1–P4 classification are described on the Pricing page; the detailed SLA appendix comes with your quote.

What we do NOT commit to

  • Uptime for self-hosted deployments you operate yourself — you run that infrastructure; we cannot measure it and will not commit on your behalf.
  • Absolute zero data loss or zero-downtime migration — we commit to the mechanism (reconciliation, parallel run, an agreed cutover window), not to an absolute promise.
  • Incidents outside the service scope — third-party systems, connectivity, or changes your own team makes.
  • One uptime figure for every customer — each customer runs a dedicated instance, so availability depends on its configuration and is written into each contract's SLA appendix; we do not publish a status page yet.
COMPLIANCE

Ready for international standards.

ISO/IEC 27001
In certification
Encryption in transit
Yes · TLS across every public channel
Encryption at rest
Yes · Dedicated Cloud: stored data encrypted by Apus · Self-hosted: follows your infrastructure configuration
Audit logs
Partial · Written at the application layer; database-level immutability is being rolled out
GDPR
Partial · Self-assessed compliance framework — no independent audit yet
DATA SOVEREIGNTY

Data stays in your business — your way.

Self-hosting, source-code handover and internal AI — sensitive data never leaves your system.

Self-hosted

Installed on your infrastructure — data stays in your business.

Source-code handover

Own the business layer, free of vendor lock-in.

Internal AI

Internal AI keeps sensitive data from leaving the system.

Need detailed security documentation?

Download the security overview or contact the Apus security team directly.

Contact security team

Download the security overview from the button above; the DPA is published on the Legal page.

Report a security vulnerability: security@apuscorp.com