Security

Data Protection

All data transmitted to and from Apex AI is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Access to customer data is strictly limited to authorized personnel with a legitimate business need.

Model Training Policy

Customer documents and data are never used to train or improve shared AI models. Your data is isolated to your organization. We do not use your inputs to fine-tune models that other customers might access.

Data Retention

Documents are retained according to your configured retention policy. By default, processed documents and their extracted data are stored for 90 days, then permanently deleted. Customers can configure shorter retention windows.

Access Controls

Role-based access controls (RBAC) allow you to define who can upload documents, review results, approve outputs, and export data. All access events are logged.

Audit Logging

Every AI suggestion, human review decision, override, and export is logged with timestamp, user ID, and rationale. Audit logs are immutable and available to account administrators.

Infrastructure

Apex AI is hosted on infrastructure with SOC 2 compliance. Regular security assessments and penetration testing are conducted.