Security You Can Verify

Enterprise-grade protection, in plain language. Here is exactly how we protect your business.

[ Deployment ]

How Your Agent Actually Runs

Every Apollo[Claw] agent lands on one of two infrastructures. Which one is a decision you make at setup, not a black box you have to take our word for.

Cloud-Hosted

Your Own Dedicated VPS

  • One VPS per agent — never shared, multi-tenant compute
  • Full-volume LUKS2 disk encryption
  • Key-based SSH only; password authentication disabled
  • Firewall restricts inbound traffic to required ports only
  • Public-facing only — webhooks and hosted assets. No client credentials live here
  • Canceling stops the VPS first — nothing is destroyed until the retention window closes

Our runtime infrastructure is ISO 27001-certified, with a SOC 2 Type I report available on request.

Self-Hosted

A Dedicated Mac Mini in Your Building

  • One Mac mini, client-owned, assigned to you and no one else
  • Full-disk encryption — FileVault, AES-128-XTS
  • Key-based SSH only; password authentication disabled
  • Firewall in stealth mode — invisible to network probes
  • Credentials isolated on-device; never transmitted to the cloud
  • No inbound access or VPN — outbound HTTPS only, to a named allowlist

We hold physical access only during setup. After that, the device is entirely yours.

Your Data, Your Infrastructure

Client runtime data lives on your VPS or your Mac mini, never a shared, multi-tenant cloud. See the deployment models above.

No Data Resale. Ever.

We do not sell, share, or monetize your data. Full stop. Your business information belongs to you.

Encrypted Everywhere

TLS with HSTS in transit. AES-256-GCM, LUKS2, and FileVault at rest, each with its key held apart from the data it protects.

Least-Privilege Access

Row-level security isolates every account's data. MFA plus an enforced second-factor step-up gates every admin action.

Reviewed Integrations

Official APIs, minimum required scopes, documented and approved by you before anything connects.

[ Written Policies ]

Formal Security Policies

A documented security policy framework, versioned and reviewed, available to enterprise clients and procurement teams on request.

Information Security Policy
Access Control Policy
Incident Management Procedure
Data Protection Policy
Data Classification Policy
Risk Assessment & Management Policy
Communications & Network Security Policy
Operations Security Policy
Compliance Policy
Vendor Management Procedure
HR Security Policy
Physical & Environmental Security Policy
[ Infrastructure ]

Built on Trusted Infrastructure

This is the infrastructure behind the Apollo[Claw] dashboard, billing, and account data, not where your agent itself runs — see “How Your Agent Actually Runs” above for that. Where we do host or manage a component, we build on providers the enterprise already trusts, each with its own mature security program and independent attestations.

Vercel

Application hosting and delivery

Supabase

Database, authentication, and storage

Stripe

Payment processing. Card data never touches our systems.

Anthropic (Claude)

The AI model layer, enterprise-grade and privacy-respecting

[ Compliance ]

Compliance Posture

Where we hold a certification directly and where we lean on a sub-processor's, named plainly rather than blurred together.

SOC 2

Our runtime infrastructure is undergoing SOC 2 - a Type I report is available on request. Apollo[Claw]'s own attestation is on our roadmap.

ISO 27001

Our runtime infrastructure holds ISO 27001 certification.

PCI DSS

SAQ-A scope. Card data is handled entirely by Stripe and never touches our systems.

GDPR / CCPA

Published privacy policy, consent-gated analytics, and deletion on request.

FERPA

We act as a school official under the institution's direct control and will execute a data-processing agreement.

HECVAT

Pre-filled questionnaire responses, ready to submit to your institution.

[ Vendor Readiness ]

What Institutional Buyers Check For

The same checklist your IT and procurement team will run through. Where something is still in progress, we say so, plainly.

Written security policies (12, InfoSec to vendor management)
Incident response plan + breach-notification commitment
Data deletion (written runbook) + export on request
Encryption in transit and at rest, on both deployment layers
Per-user data isolation (Postgres RLS) — verified live
Security headers, CSP, and per-IP rate limiting
Payment security — Stripe, PCI DSS SAQ-A scope
MFA on every admin and infrastructure account
Enforced in-app admin second factor (TOTP / AAL2 step-up)
Secrets management + automated dependency & secret scanning
Audit logging of sensitive admin actions
Published privacy policy + consent-gated analytics
HECVAT questionnaire — pre-filled, ready to submit
FERPA data-processing agreement, for education clients
Apollo[Claw]'s own SOC 2 attestation
Third-party penetration test

For IT & Procurement

Reviewing us as a vendor? We will share our vendor security packet, written policies, and a data-processing agreement for your counsel to review. Same region, same time zone, real answers.

Enterprise-ready FERPA / HECVAT-ready

Questions?

Email us at security@apolloclaw.ai with any security questions. We respond to security inquiries within one business day.

Ready to move from AI curiosity to
AI Implemented?

Schedule a free 30-minute consultation. You bring the bottlenecks, we bring the build.

Apollo[Claw] AI

Ask about AI for your business

Hi, I'm Donna, Chief Operating Officer for David Oralevich and Apollo[Claw]. How can I help you today?

Powered by Apollo[Claw]