Apptonomy Security Advisories
Last updated September 22, 2026
Version: 1.0. Effective upon publication. Last reviewed: 2026-09-22.
This page is where Apptonomy publishes advisories about security vulnerabilities in its own service that have affected, or could have affected, customer data or credentials. It is the public record; affected customers are also told directly.
Published advisories
No advisories have been published. When one is, it appears here with the date, what was affected, what was done, and what customers should do.
What we publish and when
When a critical vulnerability in the Apptonomy service has put customer data or credentials at risk, we tell every affected customer within 72 hours of confirming it: what was affected, what we did, and what they should do. Notice goes by email to each organisation’s registered contact, and an advisory is published on this page at the same time.
If the vulnerability led to a personal-data breach, the 48-hour notification commitment in our Data Processing Agreement applies instead.
We do not publish advisories for vulnerabilities that were fixed before they were reachable, or for routine dependency updates. Vulnerability reports from researchers are handled under our vulnerability disclosure policy.
Subscribe to security notices
Customers may subscribe by emailing security@apptonomy.ai with the subject “Security notices” and identifying the legal entity and the addresses to notify. Subscribed addresses receive every advisory published here, in addition to the direct notice sent to each affected organisation’s registered contact.
The version, effective date and version history on this page provide the dated change record for the page itself; each advisory carries its own publication date.
Version history
| Version | Effective date | Summary |
|---|---|---|
| 1.0 | Upon publication | Initial page: publication commitment, subscription mechanism, no advisories published |