Client Trust & Assurance | September 2026
Trust Centre – ALICE
Security, Privacy, Resilience & Assurance
Document status | Standard client-facing trust and assurance overview |
Version | 1.0 – September 2026 |
Purpose. This Trust Centre provides a concise overview of the standard security, privacy, resilience and assurance practices used by APEXE3 to protect ALICE and client information. It is designed for client due diligence and general assurance. Technical controls may vary according to deployment model, hosting location, integrations and client configuration.
1. Trust principles
APEXE3 applies a layered security model designed to protect the confidentiality, integrity and availability of ALICE, client data and supporting systems. Security controls are selected and operated using a risk-based approach and are reviewed as the platform, threat landscape and regulatory expectations evolve.
Security by design: access, network boundaries, encryption and operational controls are considered as part of platform and deployment design.
Least privilege: access is restricted to authorised users and operational personnel who require it for an approved purpose.
Client isolation: logical, network and access controls are used to separate client environments and data according to the deployment model.
Data minimisation: ALICE processes the data reasonably required to provide configured workflows, features and support.
Defence in depth: identity, network, application, monitoring, backup and incident-response controls are combined rather than relying on a single safeguard.
Continuous improvement: security procedures, dependencies, patches and operational practices are maintained as technology and risk change.
2. Security at a glance
Area | Standard position | What this means for clients |
Deployment | Managed cloud, dedicated or private deployment options | Controls are applied according to the selected deployment model and required level of isolation. |
Identity | Authorised access, roles and enterprise SSO support | Client identity policies such as MFA and conditional access can be enforced through supported identity integrations. |
Encryption | Encrypted transport and protection of stored data | Data is protected in transit using secure protocols and at rest where applicable to the managed hosting model. |
AI / models | Approved model paths and private-model options | Only data required for the requested AI task is sent to the configured model component. |
Monitoring | Operational, authentication and security event monitoring | Events are logged and reviewed to support availability, troubleshooting, security and auditability. |
Resilience | Backup, recovery and capacity controls | APEXE3-managed environments use documented recovery and backup processes appropriate to the deployment. |
Incidents | Triage, containment, remediation and client communication | Security and privacy events are assessed according to impact and urgency, with material incidents escalated. |
Privacy | Processor controls and lawful transfer mechanisms | Personal data is processed on client instructions and protected through technical and organisational measures. |
3. Platform and infrastructure security
3.1 Deployment and isolation
ALICE supports deployment models that may include APEXE3-managed cloud environments, dedicated client environments and private deployments. Where client environments are hosted by APEXE3, logical, network and access controls are used to separate workloads, storage, processing and administration according to the deployment design.
3.2 Network security
Core application and processing components are operated within controlled network boundaries.
Externally exposed services are limited to interfaces required for the configured service, such as authenticated application endpoints, APIs or secure file transfer.
Internal service communications are routed through controlled networking designed to reduce unnecessary external exposure.
IP allowlisting, private connectivity and restricted outbound access can be used where supported by the deployment and client requirements.
Secure transport protocols are used for user, API and file-transfer communications.
3.3 Identity and access management
Access is restricted to authorised users and administrators through configured roles and permissions.
ALICE supports enterprise identity integration, including SAML-based Single Sign-On where configured.
Client identity providers may enforce MFA, conditional access and other enterprise authentication policies.
Administrative and operational access to client environments is restricted to authorised personnel on a need-to-know basis.
Authentication and access events may be logged for security, troubleshooting and audit purposes.
3.4 Encryption and secure transfer
APEXE3 applies secure transport controls to protect client information in transit and appropriate encryption controls for data at rest in APEXE3-managed environments. Secure file-transfer mechanisms, authenticated APIs and encrypted web connections are used where applicable. Backup data in managed environments is protected using appropriate encryption and access controls.
4. Data protection and privacy
When APEXE3 processes personal data on behalf of a client through ALICE, the client determines the purpose and content of the processing and APEXE3 operates as a processor for that activity. The standard ALICE Data Processing Schedule describes the categories of data, typical processing activities and processor responsibilities in more detail.
Privacy area | APEXE3 approach |
Processing instructions | Personal data is processed to provide and support ALICE and in accordance with authorised client instructions, unless processing is required by law. |
Confidentiality | Personnel with authorised access are subject to confidentiality obligations and access is limited according to role and operational need. |
Data minimisation | Clients are encouraged to submit only the information required for the intended use case. ALICE does not require special-category or criminal-conviction data as a standard platform feature. |
Retention and deletion | Personal data is retained only for legitimate service, support, security, recovery or legal purposes. Client deletion or retention instructions are applied where technically and legally feasible. |
Subprocessors | Cloud, AI/model, monitoring, communications and specialist technology providers may be used where necessary. Appropriate due diligence and data-protection arrangements are applied. |
International transfers | Where required, international transfers use recognised legal mechanisms such as adequacy arrangements, approved standard data-protection clauses or recognised data-privacy frameworks. |
Data-subject support | APEXE3 provides reasonable assistance to clients responding to data-subject requests where relevant to data processed through ALICE. |
Personal data breaches | Clients are notified without undue delay after APEXE3 becomes aware of a personal data breach affecting personal data processed on their behalf. |
5. AI and model security
ALICE is an orchestration platform and may use different AI or large language model components depending on the supported deployment. These may include APEXE3-hosted models, privately hosted models or approved third-party model services.
Data is provided to the selected AI component only to the extent reasonably necessary to perform the requested ALICE operation.
Client-identifiable prompts, files and outputs are not used by APEXE3 to train shared foundation models. APEXE3 may use anonymised or aggregated operational information where clients and individuals are no longer identifiable for security, reliability and product improvement.
Where third-party model services are used, APEXE3 uses approved enterprise or private-service configurations and applies the provider controls available for security, retention and data governance.
Private model deployment options can be used where stricter isolation, data-residency or retention requirements apply.
AI-generated outputs can be probabilistic. Clients should retain appropriate human review and business controls for decisions that depend on model-generated content.
AI privacy | ALICE is designed so that model access is part of a controlled workflow rather than an unrestricted transfer of client data. The configured model path, identity controls, network route and retention posture can be selected to suit the sensitivity of the use case. |
6. Secure operations
6.1 Monitoring and logging
APEXE3 monitors managed production environments for service health, infrastructure condition and operational or security events relevant to support and incident response. Operational, authentication, access, usage and security events may be logged to support availability, troubleshooting, security investigations and auditability.
6.2 Security maintenance and vulnerability management
Platform maintenance may include security hardening, dependency and framework updates, infrastructure maintenance, bug fixes and security patches.
Security issues are prioritised according to severity, business impact, exposure and operational urgency.
Critical production-impacting issues and material security vulnerabilities receive expedited handling.
Changes are deployed using controlled operational procedures designed to reduce service disruption and preserve security.
6.3 Incident response
Security events may be detected through monitoring, support activity, automated controls or client reporting. APEXE3 follows an incident lifecycle that includes triage, severity assessment, investigation, containment or mitigation, remediation, communication and post-incident review where appropriate.
Material security incidents are escalated to appropriate technical and management personnel.
Where a personal data breach affects client personal data, notification is made without undue delay once APEXE3 becomes aware of the breach.
Clients are provided with information reasonably available to support their own risk, notification and remediation obligations.
Post-incident actions may include corrective changes, additional monitoring, patching or control improvements.
7. Resilience, backup and recovery
APEXE3-managed ALICE environments use backup, recovery, monitoring and capacity-management processes appropriate to the deployment. Backup coverage may include application data, configuration, databases, uploaded content and generated outputs. Backup retention and recovery arrangements are selected according to the service configuration and operational requirements.
Backup data is protected with access controls and encryption appropriate to the managed environment.
Recovery processes are maintained to support restoration following operational failure or data corruption.
Capacity and storage can be monitored so growth in client content, logs and generated outputs can be managed before thresholds are reached.
Enhanced resilience measures, such as additional backup frequency, replication or private infrastructure, can be supported where required.
8. Security governance and people
Security responsibilities are assigned across technical, operational and management functions.
Authorised personnel are subject to confidentiality obligations and access controls appropriate to their role.
Access to client systems and information is limited to legitimate service, support, security and administration purposes.
Security procedures and technical controls are reviewed and updated as ALICE and its supporting infrastructure evolve.
Third-party providers that process client personal data are subject to appropriate due diligence and data-protection requirements.
9. Assurance and compliance
APEXE3 maintains an information-security and compliance programme intended to support enterprise and regulated clients. Evidence is provided according to relevance, sensitivity and availability.
Assurance item | Position | Availability |
ISO/IEC 27001 | APEXE3 has completed ISO/IEC 27001 certification for its information-security management programme. | Certificate / scope available on request |
IT Security Procedures | Detailed standard security procedures covering access, network, encryption, monitoring, maintenance, backup and incidents. | Available to clients |
Data Processing Schedule | Standard ALICE processing, privacy and processor-control information. | Available to clients |
Security due diligence | Security questionnaires and reasonable supporting evidence can be provided for client assurance reviews. | On request |
Architecture information | High-level deployment, data-flow and security architecture can be provided where relevant to a client review. | On request / subject to sensitivity |
Subprocessor information | Information on material categories of subprocessors and data-processing roles can be provided for privacy review. | On request / published when applicable |
10. Client security responsibilities
Security is shared between APEXE3 and each client. APEXE3 protects the ALICE service boundary it manages; clients remain responsible for the security of their users, devices, identity systems, networks, integrations and the data they choose to submit.
Use supported SSO, MFA and conditional-access controls where available and appropriate.
Grant access according to least privilege and promptly remove access when users no longer require it.
Protect client-controlled credentials, API keys, SFTP keys and identity-provider configuration.
Submit only data that is appropriate and lawful for the intended ALICE use case.
Review AI-assisted outputs where they are used for material business, regulatory or customer decisions.
Report suspected security incidents, account compromise or unusual platform behaviour promptly.
11. Trust documents and enquiries
The following client-facing trust material can be shared to support procurement, privacy, security and risk reviews. Additional evidence may be provided where appropriate and subject to information-sensitivity controls.
Document / evidence | Purpose |
ALICE Trust Centre | High-level security, privacy, resilience and assurance overview. |
ALICE Data Processing Schedule | Standard processing activities, data categories and processor obligations. |
IT Security Procedures | Detailed technical and operational security controls. |
ISO/IEC 27001 certificate | Independent certification evidence and scope statement. |
Security questionnaire response | Client-specific due-diligence support for security, privacy and risk teams. |
Contact | Security and trust enquiries: contactus@apexe3.com | Web: www.apexe3.com |
