Security

Last updated: 2026-02-18

APRA is designed as an analytical system for project risk, schedule forecasting, portfolio visibility, and executive decision framing. We treat security as a foundational requirement throughout the trial-to-production lifecycle.

Platform safeguards

Transport security
TLS (HTTPS) with modern cipher suites
Host hardening
Firewall + SSH key auth + fail2ban
Isolation
Containerized services with least privilege
Backups
Versioned backups + restore procedures

Data protection

  • Customer Data remains yours. We use it only to provide the Service and support.
  • We recommend you avoid uploading secrets (API keys, passwords) as project content.
  • Encryption at rest: [describe your current state here].

Responsible disclosure

If you believe you found a vulnerability, email security@ordexgroup.com with details and reproduction steps.

Safe harbor: Please avoid accessing customer data and avoid service disruption.