Skip to main content

Trust Centre – ALICE

Security, privacy, resilience and assurance overview for APEXE3 ALICE, v1.0. Standard client-facing document, September 2026.

Written by Harry Khan

Client Trust & Assurance | September 2026

Trust Centre – ALICE

Security, Privacy, Resilience & Assurance

Document status

Standard client-facing trust and assurance overview

Version

1.0 – September 2026

Purpose. This Trust Centre provides a concise overview of the standard security, privacy, resilience and assurance practices used by APEXE3 to protect ALICE and client information. It is designed for client due diligence and general assurance. Technical controls may vary according to deployment model, hosting location, integrations and client configuration.

1. Trust principles

APEXE3 applies a layered security model designed to protect the confidentiality, integrity and availability of ALICE, client data and supporting systems. Security controls are selected and operated using a risk-based approach and are reviewed as the platform, threat landscape and regulatory expectations evolve.

  • Security by design: access, network boundaries, encryption and operational controls are considered as part of platform and deployment design.

  • Least privilege: access is restricted to authorised users and operational personnel who require it for an approved purpose.

  • Client isolation: logical, network and access controls are used to separate client environments and data according to the deployment model.

  • Data minimisation: ALICE processes the data reasonably required to provide configured workflows, features and support.

  • Defence in depth: identity, network, application, monitoring, backup and incident-response controls are combined rather than relying on a single safeguard.

  • Continuous improvement: security procedures, dependencies, patches and operational practices are maintained as technology and risk change.

2. Security at a glance

Area

Standard position

What this means for clients

Deployment

Managed cloud, dedicated or private deployment options

Controls are applied according to the selected deployment model and required level of isolation.

Identity

Authorised access, roles and enterprise SSO support

Client identity policies such as MFA and conditional access can be enforced through supported identity integrations.

Encryption

Encrypted transport and protection of stored data

Data is protected in transit using secure protocols and at rest where applicable to the managed hosting model.

AI / models

Approved model paths and private-model options

Only data required for the requested AI task is sent to the configured model component.

Monitoring

Operational, authentication and security event monitoring

Events are logged and reviewed to support availability, troubleshooting, security and auditability.

Resilience

Backup, recovery and capacity controls

APEXE3-managed environments use documented recovery and backup processes appropriate to the deployment.

Incidents

Triage, containment, remediation and client communication

Security and privacy events are assessed according to impact and urgency, with material incidents escalated.

Privacy

Processor controls and lawful transfer mechanisms

Personal data is processed on client instructions and protected through technical and organisational measures.

3. Platform and infrastructure security

3.1 Deployment and isolation

ALICE supports deployment models that may include APEXE3-managed cloud environments, dedicated client environments and private deployments. Where client environments are hosted by APEXE3, logical, network and access controls are used to separate workloads, storage, processing and administration according to the deployment design.

3.2 Network security

  • Core application and processing components are operated within controlled network boundaries.

  • Externally exposed services are limited to interfaces required for the configured service, such as authenticated application endpoints, APIs or secure file transfer.

  • Internal service communications are routed through controlled networking designed to reduce unnecessary external exposure.

  • IP allowlisting, private connectivity and restricted outbound access can be used where supported by the deployment and client requirements.

  • Secure transport protocols are used for user, API and file-transfer communications.

3.3 Identity and access management

  • Access is restricted to authorised users and administrators through configured roles and permissions.

  • ALICE supports enterprise identity integration, including SAML-based Single Sign-On where configured.

  • Client identity providers may enforce MFA, conditional access and other enterprise authentication policies.

  • Administrative and operational access to client environments is restricted to authorised personnel on a need-to-know basis.

  • Authentication and access events may be logged for security, troubleshooting and audit purposes.

3.4 Encryption and secure transfer

APEXE3 applies secure transport controls to protect client information in transit and appropriate encryption controls for data at rest in APEXE3-managed environments. Secure file-transfer mechanisms, authenticated APIs and encrypted web connections are used where applicable. Backup data in managed environments is protected using appropriate encryption and access controls.

4. Data protection and privacy

When APEXE3 processes personal data on behalf of a client through ALICE, the client determines the purpose and content of the processing and APEXE3 operates as a processor for that activity. The standard ALICE Data Processing Schedule describes the categories of data, typical processing activities and processor responsibilities in more detail.

Privacy area

APEXE3 approach

Processing instructions

Personal data is processed to provide and support ALICE and in accordance with authorised client instructions, unless processing is required by law.

Confidentiality

Personnel with authorised access are subject to confidentiality obligations and access is limited according to role and operational need.

Data minimisation

Clients are encouraged to submit only the information required for the intended use case. ALICE does not require special-category or criminal-conviction data as a standard platform feature.

Retention and deletion

Personal data is retained only for legitimate service, support, security, recovery or legal purposes. Client deletion or retention instructions are applied where technically and legally feasible.

Subprocessors

Cloud, AI/model, monitoring, communications and specialist technology providers may be used where necessary. Appropriate due diligence and data-protection arrangements are applied.

International transfers

Where required, international transfers use recognised legal mechanisms such as adequacy arrangements, approved standard data-protection clauses or recognised data-privacy frameworks.

Data-subject support

APEXE3 provides reasonable assistance to clients responding to data-subject requests where relevant to data processed through ALICE.

Personal data breaches

Clients are notified without undue delay after APEXE3 becomes aware of a personal data breach affecting personal data processed on their behalf.

5. AI and model security

ALICE is an orchestration platform and may use different AI or large language model components depending on the supported deployment. These may include APEXE3-hosted models, privately hosted models or approved third-party model services.

  • Data is provided to the selected AI component only to the extent reasonably necessary to perform the requested ALICE operation.

  • Client-identifiable prompts, files and outputs are not used by APEXE3 to train shared foundation models. APEXE3 may use anonymised or aggregated operational information where clients and individuals are no longer identifiable for security, reliability and product improvement.

  • Where third-party model services are used, APEXE3 uses approved enterprise or private-service configurations and applies the provider controls available for security, retention and data governance.

  • Private model deployment options can be used where stricter isolation, data-residency or retention requirements apply.

  • AI-generated outputs can be probabilistic. Clients should retain appropriate human review and business controls for decisions that depend on model-generated content.

AI privacy

ALICE is designed so that model access is part of a controlled workflow rather than an unrestricted transfer of client data. The configured model path, identity controls, network route and retention posture can be selected to suit the sensitivity of the use case.

6. Secure operations

6.1 Monitoring and logging

APEXE3 monitors managed production environments for service health, infrastructure condition and operational or security events relevant to support and incident response. Operational, authentication, access, usage and security events may be logged to support availability, troubleshooting, security investigations and auditability.

6.2 Security maintenance and vulnerability management

  • Platform maintenance may include security hardening, dependency and framework updates, infrastructure maintenance, bug fixes and security patches.

  • Security issues are prioritised according to severity, business impact, exposure and operational urgency.

  • Critical production-impacting issues and material security vulnerabilities receive expedited handling.

  • Changes are deployed using controlled operational procedures designed to reduce service disruption and preserve security.

6.3 Incident response

Security events may be detected through monitoring, support activity, automated controls or client reporting. APEXE3 follows an incident lifecycle that includes triage, severity assessment, investigation, containment or mitigation, remediation, communication and post-incident review where appropriate.

  • Material security incidents are escalated to appropriate technical and management personnel.

  • Where a personal data breach affects client personal data, notification is made without undue delay once APEXE3 becomes aware of the breach.

  • Clients are provided with information reasonably available to support their own risk, notification and remediation obligations.

  • Post-incident actions may include corrective changes, additional monitoring, patching or control improvements.

7. Resilience, backup and recovery

APEXE3-managed ALICE environments use backup, recovery, monitoring and capacity-management processes appropriate to the deployment. Backup coverage may include application data, configuration, databases, uploaded content and generated outputs. Backup retention and recovery arrangements are selected according to the service configuration and operational requirements.

  • Backup data is protected with access controls and encryption appropriate to the managed environment.

  • Recovery processes are maintained to support restoration following operational failure or data corruption.

  • Capacity and storage can be monitored so growth in client content, logs and generated outputs can be managed before thresholds are reached.

  • Enhanced resilience measures, such as additional backup frequency, replication or private infrastructure, can be supported where required.

8. Security governance and people

  • Security responsibilities are assigned across technical, operational and management functions.

  • Authorised personnel are subject to confidentiality obligations and access controls appropriate to their role.

  • Access to client systems and information is limited to legitimate service, support, security and administration purposes.

  • Security procedures and technical controls are reviewed and updated as ALICE and its supporting infrastructure evolve.

  • Third-party providers that process client personal data are subject to appropriate due diligence and data-protection requirements.

9. Assurance and compliance

APEXE3 maintains an information-security and compliance programme intended to support enterprise and regulated clients. Evidence is provided according to relevance, sensitivity and availability.

Assurance item

Position

Availability

ISO/IEC 27001

APEXE3 has completed ISO/IEC 27001 certification for its information-security management programme.

Certificate / scope available on request

IT Security Procedures

Detailed standard security procedures covering access, network, encryption, monitoring, maintenance, backup and incidents.

Available to clients

Data Processing Schedule

Standard ALICE processing, privacy and processor-control information.

Available to clients

Security due diligence

Security questionnaires and reasonable supporting evidence can be provided for client assurance reviews.

On request

Architecture information

High-level deployment, data-flow and security architecture can be provided where relevant to a client review.

On request / subject to sensitivity

Subprocessor information

Information on material categories of subprocessors and data-processing roles can be provided for privacy review.

On request / published when applicable

10. Client security responsibilities

Security is shared between APEXE3 and each client. APEXE3 protects the ALICE service boundary it manages; clients remain responsible for the security of their users, devices, identity systems, networks, integrations and the data they choose to submit.

  • Use supported SSO, MFA and conditional-access controls where available and appropriate.

  • Grant access according to least privilege and promptly remove access when users no longer require it.

  • Protect client-controlled credentials, API keys, SFTP keys and identity-provider configuration.

  • Submit only data that is appropriate and lawful for the intended ALICE use case.

  • Review AI-assisted outputs where they are used for material business, regulatory or customer decisions.

  • Report suspected security incidents, account compromise or unusual platform behaviour promptly.

11. Trust documents and enquiries

The following client-facing trust material can be shared to support procurement, privacy, security and risk reviews. Additional evidence may be provided where appropriate and subject to information-sensitivity controls.

Document / evidence

Purpose

ALICE Trust Centre

High-level security, privacy, resilience and assurance overview.

ALICE Data Processing Schedule

Standard processing activities, data categories and processor obligations.

IT Security Procedures

Detailed technical and operational security controls.

ISO/IEC 27001 certificate

Independent certification evidence and scope statement.

Security questionnaire response

Client-specific due-diligence support for security, privacy and risk teams.

Contact

Security and trust enquiries: contactus@apexe3.com | Web: www.apexe3.com

Did this answer your question?