Security

Last updated: 2026-06-01 · Version 1.0

APRA is designed as an analytical system for project risk, schedule forecasting, portfolio visibility, and executive decision framing. We treat security as a foundational requirement throughout the trial-to-production lifecycle.

Platform safeguards

Transport security
TLS (HTTPS) with modern cipher suites
Host hardening
Firewall + SSH key auth + fail2ban
Isolation
Containerized services with least privilege
Backups
Versioned backups + restore procedures

Data protection

  • Customer Data remains yours. We use it only to provide the Service and support.
  • We recommend you avoid uploading secrets (API keys, passwords) as project content.
  • Encryption at rest: APRA is deployed on hardened cloud infrastructure. Database and volume encryption depend on the active hosting/storage configuration and are reviewed as part of production security operations.
  • Access control: application access is authenticated and role-based. Customers should only grant access to authorized personnel.
  • Data minimization: customers should avoid uploading secrets, credentials, payment card data, protected health information, or other highly sensitive information unless explicitly agreed in writing.

Backups and recovery

APRA is designed to support versioned backups and restore procedures. Backup frequency, retention, and recovery objectives may vary by deployment environment and customer agreement.

Incident response

If ORDEX SYSTEMS becomes aware of a material security incident affecting customer data, we will evaluate the incident and provide notifications as required by applicable law, contractual obligations, and operational circumstances.

Responsible disclosure

If you believe you found a vulnerability, email security@ordexgroup.com with details and reproduction steps.

Safe harbor: Please avoid accessing customer data and avoid service disruption.