Your Data Stays Yours

Enterprise-grade protection, in plain language. Here is exactly how we protect your business.

Your Data, Your Infrastructure

Apollo[Claw] agents are built on your infrastructure wherever possible. Your data does not pass through servers we own or control unless it is a requirement of a specific integration you have approved.

No Data Resale. Ever.

We do not sell, share, or monetize your data. Full stop. Your business information, client data, and operational details belong to you.

Encrypted in Transit and at Rest

All data in transit is encrypted using TLS 1.3 with HSTS. Data at rest is encrypted using AES-256 where applicable. Credentials and API keys are stored in encrypted vaults using AES-256-GCM, with the key held separately from the data it protects, never in plaintext.

Access Controls

Apollo[Claw] operates on a least-privilege model. Your agent only has access to the specific tools and data it needs to perform its defined tasks, and access is reviewed when scope changes. Row-level security isolates every account's data from every other account's at the database layer. Every administrative and infrastructure account requires multi-factor authentication, with an enforced authenticator-app second factor before any privileged admin action.

Third-Party Integrations

When your AI agent connects to third-party tools (Gmail, CRMs, calendars), those connections are made using official API protocols with the minimum required permissions. We document every integration and require your explicit approval.

Governance & Operational Security

The confidentiality, integrity, and availability of your data are not afterthoughts. They are the foundation of every decision we make about architecture, access, and operations. Apollo[Claw] operates under a formal set of written policies covering information security, access control, incident response, data classification, risk management, vendor management, and more.

Every public-facing endpoint is rate-limited, and every response carries standard security headers and a content-security policy. We maintain an incident-response plan with a breach-notification commitment, log sensitive administrative actions, and continuously scan our code for vulnerabilities and exposed secrets. Where we host or manage components, backups run with point-in-time recovery and are encrypted at rest.

Written policies, our vendor security packet, and a data-processing agreement are available to IT and procurement teams on request.

[ Written Policies ]

Formal Security Policies

Apollo[Claw] maintains a documented security policy framework. All policies are versioned, reviewed, and available to enterprise clients and procurement teams on request.

Information Security Policy
Access Control Policy
Incident Management Procedure
Data Protection Policy
Data Classification Policy
Risk Assessment & Management Policy
Communications & Network Security Policy
Operations Security Policy
Compliance Policy
Vendor Management Procedure
HR Security Policy
Physical & Environmental Security Policy
[ Infrastructure ]

Built on Trusted Infrastructure

Where a deployment includes components we host or manage, we build on providers the enterprise already trusts, each with its own mature security program and independent attestations.

Vercel

Application hosting and delivery

Supabase

Database, authentication, and storage

Stripe

Payment processing. Card data never touches our systems.

Anthropic (Claude)

The AI model layer, enterprise-grade and privacy-respecting

Compliance & Privacy

Privacy (GDPR): We use Google Analytics for aggregate traffic measurement and never sell or share your data. A cookie consent banner and a published privacy policy are in progress. Data deletion is available on request today.
Payments (PCI DSS): All card data is handled by Stripe under PCI DSS and never reaches our systems.
SOC 2: Apollo[Claw] is SOC 2 Type I compliant, with an audit report available on request. SOC 2 Type II is on track for completion by the end of September 2026.
Education clients (FERPA / HECVAT): For universities and student-facing programs, Apollo[Claw] is FERPA-aware and will execute a data-processing agreement, with completed HECVAT responses available.
Documentation on request: Written security policies, a data-processing agreement, and a vendor security packet are available to IT and procurement teams.
[ Vendor Readiness ]

What Institutional Buyers Check For

The same checklist your IT and procurement team will run through. Where something is still in progress, we say so, plainly.

Written security policies
12 formal policies covering InfoSec, access control, incident response, data classification, risk management, and more
Incident response plan
Documented, with a breach-notification commitment
Data classification policy
Formal data classification framework in place
Data export & deletion
Deletion on request today, self-service export in progress
Encryption in transit and at rest
TLS 1.3, AES-256, keys held outside the data they protect
Per-user data isolation
Row-level security, verified on every table
Application hardening
Rate limiting on the assistant endpoint; security headers and CSP in progress
Payment security
Stripe, PCI DSS SAQ-A scope, card data never touches our systems
MFA on every admin account
Plus an enforced second factor before privileged actions
Dependency & secret scanning
Automated, on every code change
Audit logging
Platform-level logging in place, application audit trail in progress
Cookie consent banner
In progress, ask for current status
Published privacy policy
In progress, available on request in the meantime
HECVAT responses (education)
Pre-filled and ready to submit
FERPA data-processing agreement
Available for education clients
SOC 2
In progress, audit report available on request
Third-party penetration test
On our roadmap, ask for current status

For IT & Procurement

Reviewing us as a vendor? We will share our vendor security packet, written policies, and a data-processing agreement for your counsel to review. Same region, same time zone, real answers.

Questions?

Email us at security@apolloclaw.ai with any security questions. We respond to security inquiries within one business day.

Ready to move from AI curiosity to
AI Implemented?

Schedule a free 30-minute consultation. You bring the bottlenecks, we bring the build.

[Weekly Intelligence]

The Weekly Claw

What happened in AI last week and what to watch this week. Every Monday.

No spam. Unsubscribe anytime.

Apollo[Claw] AI

Ask about AI for your business

Hi, I'm Donna, Chief Operating Officer for David Oralevich and Apollo[Claw]. How can I help you today?

Powered by Apollo[Claw]