Security
APRA is designed as an analytical system for project risk, schedule forecasting, portfolio visibility, and executive decision framing. We treat security as a foundational requirement throughout the trial-to-production lifecycle.
Platform safeguards
Data protection
- Customer Data remains yours. We use it only to provide the Service and support.
- We recommend you avoid uploading secrets (API keys, passwords) as project content.
- Encryption at rest: APRA is deployed on hardened cloud infrastructure. Database and volume encryption depend on the active hosting/storage configuration and are reviewed as part of production security operations.
- Access control: application access is authenticated and role-based. Customers should only grant access to authorized personnel.
- Data minimization: customers should avoid uploading secrets, credentials, payment card data, protected health information, or other highly sensitive information unless explicitly agreed in writing.
Backups and recovery
APRA is designed to support versioned backups and restore procedures. Backup frequency, retention, and recovery objectives may vary by deployment environment and customer agreement.
Incident response
If ORDEX SYSTEMS becomes aware of a material security incident affecting customer data, we will evaluate the incident and provide notifications as required by applicable law, contractual obligations, and operational circumstances.
Responsible disclosure
If you believe you found a vulnerability, email security@ordexgroup.com with details and reproduction steps.
Safe harbor: Please avoid accessing customer data and avoid service disruption.