Your Data Stays Yours
Enterprise-grade protection, in plain language. Here is exactly how we protect your business.
Your Data, Your Infrastructure
No Data Resale. Ever.
Encrypted in Transit and at Rest
Access Controls
Third-Party Integrations
Governance & Operational Security
The confidentiality, integrity, and availability of your data are not afterthoughts. They are the foundation of every decision we make about architecture, access, and operations. Apollo[Claw] operates under a formal set of written policies covering information security, access control, incident response, data classification, risk management, vendor management, and more.
Every public-facing endpoint is rate-limited, and every response carries standard security headers and a content-security policy. We maintain an incident-response plan with a breach-notification commitment, log sensitive administrative actions, and continuously scan our code for vulnerabilities and exposed secrets. Where we host or manage components, backups run with point-in-time recovery and are encrypted at rest.
Written policies, our vendor security packet, and a data-processing agreement are available to IT and procurement teams on request.
Formal Security Policies
Apollo[Claw] maintains a documented security policy framework. All policies are versioned, reviewed, and available to enterprise clients and procurement teams on request.
Built on Trusted Infrastructure
Where a deployment includes components we host or manage, we build on providers the enterprise already trusts, each with its own mature security program and independent attestations.
Vercel
Application hosting and delivery
Supabase
Database, authentication, and storage
Stripe
Payment processing. Card data never touches our systems.
Anthropic (Claude)
The AI model layer, enterprise-grade and privacy-respecting
Compliance & Privacy
What Institutional Buyers Check For
The same checklist your IT and procurement team will run through. Where something is still in progress, we say so, plainly.
12 formal policies covering InfoSec, access control, incident response, data classification, risk management, and more
Documented, with a breach-notification commitment
Formal data classification framework in place
Deletion on request today, self-service export in progress
TLS 1.3, AES-256, keys held outside the data they protect
Row-level security, verified on every table
Rate limiting on the assistant endpoint; security headers and CSP in progress
Stripe, PCI DSS SAQ-A scope, card data never touches our systems
Plus an enforced second factor before privileged actions
Automated, on every code change
Platform-level logging in place, application audit trail in progress
In progress, ask for current status
In progress, available on request in the meantime
Pre-filled and ready to submit
Available for education clients
In progress, audit report available on request
On our roadmap, ask for current status
For IT & Procurement
Reviewing us as a vendor? We will share our vendor security packet, written policies, and a data-processing agreement for your counsel to review. Same region, same time zone, real answers.
Questions?
Email us at security@apolloclaw.ai with any security questions. We respond to security inquiries within one business day.