Security
APRA is designed as an analytical system for project risk, schedule forecasting, portfolio visibility, and executive decision framing. We treat security as a foundational requirement throughout the trial-to-production lifecycle.
Platform safeguards
Transport security
TLS (HTTPS) with modern cipher suites
Host hardening
Firewall + SSH key auth + fail2ban
Isolation
Containerized services with least privilege
Backups
Versioned backups + restore procedures
Data protection
- Customer Data remains yours. We use it only to provide the Service and support.
- We recommend you avoid uploading secrets (API keys, passwords) as project content.
- Encryption at rest: [describe your current state here].
Responsible disclosure
If you believe you found a vulnerability, email security@ordexgroup.com with details and reproduction steps.
Safe harbor: Please avoid accessing customer data and avoid service disruption.