Security You Can Verify
Enterprise-grade protection, in plain language. Here is exactly how we protect your business.
How Your Agent Actually Runs
Every Apollo[Claw] agent lands on one of two infrastructures. Which one is a decision you make at setup, not a black box you have to take our word for.
Cloud-Hosted
Your Own Dedicated VPS
- One VPS per agent — never shared, multi-tenant compute
- Full-volume LUKS2 disk encryption
- Key-based SSH only; password authentication disabled
- Firewall restricts inbound traffic to required ports only
- Public-facing only — webhooks and hosted assets. No client credentials live here
- Canceling stops the VPS first — nothing is destroyed until the retention window closes
Our runtime infrastructure is ISO 27001-certified, with a SOC 2 Type I report available on request.
Self-Hosted
A Dedicated Mac Mini in Your Building
- One Mac mini, client-owned, assigned to you and no one else
- Full-disk encryption — FileVault, AES-128-XTS
- Key-based SSH only; password authentication disabled
- Firewall in stealth mode — invisible to network probes
- Credentials isolated on-device; never transmitted to the cloud
- No inbound access or VPN — outbound HTTPS only, to a named allowlist
We hold physical access only during setup. After that, the device is entirely yours.
Your Data, Your Infrastructure
Client runtime data lives on your VPS or your Mac mini, never a shared, multi-tenant cloud. See the deployment models above.
No Data Resale. Ever.
We do not sell, share, or monetize your data. Full stop. Your business information belongs to you.
Encrypted Everywhere
TLS with HSTS in transit. AES-256-GCM, LUKS2, and FileVault at rest, each with its key held apart from the data it protects.
Least-Privilege Access
Row-level security isolates every account's data. MFA plus an enforced second-factor step-up gates every admin action.
Reviewed Integrations
Official APIs, minimum required scopes, documented and approved by you before anything connects.
Formal Security Policies
A documented security policy framework, versioned and reviewed, available to enterprise clients and procurement teams on request.
Built on Trusted Infrastructure
This is the infrastructure behind the Apollo[Claw] dashboard, billing, and account data, not where your agent itself runs — see “How Your Agent Actually Runs” above for that. Where we do host or manage a component, we build on providers the enterprise already trusts, each with its own mature security program and independent attestations.
Vercel
Application hosting and delivery
Supabase
Database, authentication, and storage
Stripe
Payment processing. Card data never touches our systems.
Anthropic (Claude)
The AI model layer, enterprise-grade and privacy-respecting
Compliance Posture
Where we hold a certification directly and where we lean on a sub-processor's, named plainly rather than blurred together.
Our runtime infrastructure is undergoing SOC 2 - a Type I report is available on request. Apollo[Claw]'s own attestation is on our roadmap.
Our runtime infrastructure holds ISO 27001 certification.
SAQ-A scope. Card data is handled entirely by Stripe and never touches our systems.
Published privacy policy, consent-gated analytics, and deletion on request.
We act as a school official under the institution's direct control and will execute a data-processing agreement.
Pre-filled questionnaire responses, ready to submit to your institution.
What Institutional Buyers Check For
The same checklist your IT and procurement team will run through. Where something is still in progress, we say so, plainly.
For IT & Procurement
Reviewing us as a vendor? We will share our vendor security packet, written policies, and a data-processing agreement for your counsel to review. Same region, same time zone, real answers.
Questions?
Email us at security@apolloclaw.ai with any security questions. We respond to security inquiries within one business day.