SECURITY AND ASSURANCE

Security at Apptonomy

How we protect the store data and credentials you connect, how we answer vendor security assessments, and where we stand on independent assurance. Each page below says what is in place today and what is still planned.

Last reviewed:

Security pages

Published documents

Data Processing Agreement
The terms under which we process personal data for you.
Subprocessors
Every provider that may process personal data for Apptonomy, with purpose and location.
Privacy Notice
What personal data we collect, why, and your rights over it.
Vulnerability disclosure policy
How to report a vulnerability and how we handle reports.
security.txt
Machine-readable security contact, per RFC 9116.
Security advisories
Published advisories and how to subscribe to security notices.

Available on request

Ask at security@apptonomy.ai for the documents behind these pages. Items marked NDA are shared once a non-disclosure agreement is in place.

  • Customer policy extract: our Information Security Policy and its sixteen annexes
  • Platform architecture diagram (NDA)
  • Credential-encryption design (NDA)
  • A walkthrough of the evidence behind our questionnaire answers (NDA)

Independent assurance

Apptonomy does not currently have a SOC 2 report, and no SOC 2 examination is currently underway.

We do not hold an ISO/IEC 27001 certificate. Our first independent penetration test is planned for Q1 2027.

Security questions

Report a vulnerability or ask a security question at security@apptonomy.ai.

security@apptonomy.ai