APEXE3 Client Trust Material | September 2026
IT Security Procedures
APEXE3 Standard Client-Facing Security Procedures
Technical and organisational security controls for APEXE3-managed services and client information.
Document status | Standard client-facing security procedures |
Audience | Clients, prospective clients, security, privacy, risk, compliance and procurement teams |
Related trust material | Trust Centre, Data Processing Schedule, Service Level Agreement and Support Services Schedule |
Scope. These Procedures describe APEXE3's standard security practices for protecting client information and the confidentiality, integrity and availability of APEXE3-managed services. They are designed to be shareable across APEXE3's client base. Individual technical controls can vary by deployment model, hosting location, integration pattern, data type and service configuration.
1. Security principles and governance
APEXE3 applies a layered, risk-based security model. Security controls are reviewed as services, infrastructure, threat conditions and regulatory expectations evolve. The standard operating principles are:
security by design - network boundaries, identity, encryption and operational controls are considered as part of service and deployment design;
least privilege - access is limited to authorised users and personnel who require it for an approved purpose;
client separation - logical, network and access controls are used to separate client environments and data according to the deployment model;
data minimisation - only information reasonably required to provide, secure and support the service should be processed;
defence in depth - identity, network, application, monitoring, backup and incident-response controls are combined rather than relying on a single safeguard; and
continuous improvement - security procedures, dependencies, patches and operational practices are maintained as technology and risk change.
Security responsibilities are assigned across technical, operational and management functions. Security procedures and supporting controls are reviewed and updated as APEXE3 services and infrastructure evolve.
2. Hosting, deployment and environment isolation
2.1 Deployment models
APEXE3 services may be delivered through APEXE3-managed cloud environments, dedicated client environments, private deployments or other supported hosting models. Security controls are applied according to the selected architecture and the portion of the technology stack managed by APEXE3.
2.2 Client and workload separation
Where APEXE3 hosts or manages client environments, logical, network and access controls are used to separate client workloads, storage, processing and administration in accordance with the deployment design. Dedicated or private deployment options may be used where greater isolation is required and supported.
2.3 Production and non-production environments
Production and non-production environments are separated where the service architecture provides distinct environments. Production data is not intentionally introduced into non-production environments unless required for an approved operational purpose and handled using appropriate access, confidentiality and data-protection controls.
2.4 Hosting location and data residency
Hosting regions and data-location controls depend on the relevant service and deployment. Where supported, APEXE3 can configure services to align with client data-residency, regulatory and governance requirements. APEXE3 does not represent that every service or third-party dependency is available in every jurisdiction.
3. Network and communications security
3.1 Controlled network boundaries
Core application, processing and storage components in APEXE3-managed environments operate within controlled network boundaries. Internal service communications are routed through managed networking intended to reduce unnecessary external exposure and limit traffic to required service paths.
3.2 External interfaces
externally exposed interfaces are limited to those required for the service, such as authenticated application endpoints, APIs or secure file-transfer services;
secure transport protocols are used for user, API and file-transfer communications;
IP allowlisting, private connectivity and restricted network routes can be used where supported by the deployment; and
network configuration changes that materially affect exposure or connectivity are handled through controlled operational change procedures.
3.3 Secure file transfer
Where secure file transfer is provided, APEXE3 uses authenticated and encrypted transfer mechanisms appropriate to the service. SFTP implementations may use host-key validation and public-key authentication where supported.
4. Identity, authentication and access control
4.1 Authorised access
Access to APEXE3 services and client environments is restricted to authorised users and authorised operational personnel. Permissions are granted according to role, business need and the functions required to provide or use the service.
4.2 Enterprise identity integration
APEXE3 services may support enterprise identity federation, including SAML-based Single Sign-On. Where client-managed identity providers are used, clients can apply their own authentication policies such as multi-factor authentication, conditional access and user-lifecycle controls through supported integrations.
4.3 Privileged and operational access
Administrative and operational access to client environments, logs, backups and supporting infrastructure is limited to personnel who require access for legitimate service, support, security or administration purposes. Access to confidential client information is handled on a need-to-know basis.
4.4 Authentication and access records
Authentication, access and administrative events may be logged where supported to assist with security monitoring, troubleshooting, incident investigation and auditability.
5. Encryption and protection of client data
5.1 Data in transit
APEXE3 uses secure transport protocols to protect information in transit across APEXE3-managed service interfaces. HTTPS/TLS, authenticated APIs and secure file-transfer protocols are used where applicable to the service.
5.2 Data at rest
Appropriate encryption controls are applied to client data stored in APEXE3-managed environments using the capabilities of the relevant hosting and storage platform. Backup data in managed environments is protected using appropriate encryption and access controls.
5.3 Secrets and credentials
Clients should not send passwords, private keys, access tokens or other secrets through ordinary support messages unless APEXE3 has provided an approved secure transfer method. Client-controlled credentials and keys remain the responsibility of the client.
5.4 Data minimisation and retention
APEXE3 aims to process and retain information only to the extent reasonably required to provide, secure, support and recover the relevant service, or to meet legal and compliance requirements. Personal-data retention and deletion practices are described in APEXE3's Data Processing Schedule.
6. Application, integration and AI security
6.1 Controlled service components and integrations
Application services, processing components, data stores, APIs and integrations are operated within the security boundary appropriate to the deployment. Integrations are enabled only where required for the configured service and are subject to available authentication, network and access controls.
6.2 AI and model services
Where an APEXE3 service uses AI or large language model components, model access is incorporated into a controlled workflow. APEXE3 may use APEXE3-hosted models, privately hosted models or approved third-party enterprise model services depending on the service and deployment.
data is provided to a configured model component only to the extent reasonably necessary to perform the requested operation;
client-identifiable prompts, files and outputs are not used by APEXE3 to train shared foundation models;
where third-party model services are used, APEXE3 applies the provider security, retention and data-governance controls available for the selected service; and
private or dedicated model options may be used where supported for use cases requiring greater isolation, data-residency control or a stricter retention posture.
AI-generated outputs may be probabilistic. Clients should maintain appropriate human review and business controls for material decisions that depend on AI-generated content.
7. Monitoring, logging and operational security
7.1 Monitoring
APEXE3 monitors managed production environments for service health, infrastructure condition and operational or security events relevant to support and incident response. Monitoring depth depends on the service architecture and the infrastructure managed by APEXE3.
7.2 Logging
Operational, authentication, access, usage and security events may be logged to support availability management, troubleshooting, security investigations and auditability. Access to logs is restricted according to operational need and the sensitivity of the information recorded.
7.3 Capacity and availability
Where relevant, APEXE3 monitors storage, compute or service-capacity indicators so that expected growth and operational thresholds can be managed before they materially affect service availability.
8. Vulnerability management, maintenance and change control
8.1 Security maintenance
APEXE3 maintains APEXE3-managed services through a combination of security hardening, infrastructure maintenance, dependency and framework updates, bug fixes, hotfixes and security patches appropriate to the service.
8.2 Vulnerability prioritisation
Security issues are assessed and prioritised according to factors such as severity, exploitability, business impact, exposure and operational urgency. Critical production-impacting issues and material security vulnerabilities receive expedited handling in accordance with APEXE3's incident and support processes.
8.3 Change control
Changes to APEXE3-managed production services are deployed through controlled operational procedures designed to reduce avoidable disruption and preserve security. Emergency changes may be expedited where reasonably necessary to address an active threat, serious vulnerability, material instability or risk to data integrity.
9. Backup, recovery and resilience
APEXE3-managed services use backup, recovery, monitoring and capacity-management processes appropriate to the deployment and data type. Backup coverage may include application data, configuration, databases, client-provided content and generated outputs where those items are persistently stored by the service.
backup data is protected using access controls and encryption appropriate to the managed environment;
access to backup and recovery functions is restricted to authorised personnel;
restoration activity is prioritised according to incident severity and service impact;
recovery uses the latest viable backup or recovery point available for the affected service; and
additional backup frequency, replication or enhanced resilience can be supported where the service architecture provides those options.
Backup frequency, retention and recovery capabilities vary between services and deployment models. APEXE3 therefore does not apply a single universal recovery point or recovery time commitment to every service unless separately stated for that service.
10. Security incident management
10.1 Detection and reporting
Security events may be identified through monitoring, support activity, automated controls, provider notifications or client reporting. Clients should report suspected security incidents, account compromise or unusual service behaviour promptly through an APEXE3-designated support or security contact.
10.2 Incident response lifecycle
initial triage and severity assessment;
technical investigation and identification of affected systems or data;
containment, mitigation or remediation activity as appropriate;
internal escalation to appropriate technical and management personnel;
client communication for material incidents and progress updates where appropriate;
service restoration and resolution confirmation; and
post-incident review and corrective actions where appropriate.
10.3 Personal data breaches
Where APEXE3 becomes aware of a personal data breach affecting personal data processed on behalf of a client, APEXE3 will notify the affected client without undue delay and provide information reasonably available to support the client's assessment, notification and remediation obligations.
11. Personnel, confidentiality and third parties
11.1 Personnel access and confidentiality
Personnel with authorised access to client systems or information are subject to confidentiality obligations and access controls appropriate to their role. Access is limited to legitimate service, support, security, administration and approved operational purposes.
11.2 Third-party providers and subprocessors
APEXE3 may use cloud, communications, monitoring, AI/model and specialist technology providers to deliver or support services. Providers that process client personal data are subject to appropriate due diligence and data-protection arrangements. Material categories of subprocessors can be disclosed through APEXE3's privacy and trust materials.
11.3 International transfers
Where personal data is transferred internationally, APEXE3 uses recognised transfer mechanisms as required by applicable data-protection law, such as adequacy arrangements, approved standard contractual clauses or recognised data-privacy frameworks.
12. Client security responsibilities
Security is shared between APEXE3 and each client. APEXE3 protects the service boundary and infrastructure it manages; clients remain responsible for controls under their own management. Clients should:
protect their users, endpoints, networks, identity systems and integrations used to access APEXE3 services;
use supported SSO, multi-factor authentication and conditional-access controls where available and appropriate;
grant access according to least privilege and promptly remove access when users no longer require it;
protect client-controlled credentials, API keys, SFTP keys and identity-provider configuration;
submit only information that is appropriate and lawful for the intended service use;
review AI-assisted outputs where used for material business, regulatory or customer decisions; and
report suspected security incidents, credential compromise or unusual service behaviour promptly.
13. Assurance, review and document maintenance
APEXE3 maintains an information-security and compliance programme intended to support enterprise and regulated clients. APEXE3 has completed ISO/IEC 27001 certification for its information-security management programme; certification evidence and scope information are available on request, subject to information-sensitivity controls.
These Procedures are reviewed and updated as APEXE3 services, technology and operating practices evolve. Updates are intended to maintain or improve APEXE3's baseline security posture. Client-specific security questionnaires and reasonable supporting evidence may be provided as part of due-diligence and assurance reviews.
Appendix A. Security control summary
Security domain | Standard APEXE3 procedure |
Governance | Risk-based security programme; assigned security responsibilities; periodic procedure review. |
Deployment | Managed cloud, dedicated and private deployment patterns supported where applicable. |
Isolation | Logical, network and access controls used to separate client workloads and information. |
Network | Controlled network boundaries; external exposure limited to required service interfaces. |
Identity | Authorised access, role-based permissions and enterprise SSO support where configured. |
Encryption | Secure transport protocols; encryption controls for stored data and backups in managed environments. |
File transfer | Authenticated and encrypted transfer mechanisms; SFTP public-key authentication where supported. |
Monitoring | Service health, infrastructure and security-event monitoring appropriate to the managed environment. |
Logging | Operational, authentication, access and security events may be retained for troubleshooting and auditability. |
Vulnerability management | Risk-based identification, prioritisation, patching and remediation of security issues. |
Change control | Controlled production changes; expedited emergency changes for urgent security or stability risks. |
Backup & recovery | Backup, restoration and resilience measures appropriate to the service and deployment. |
Incident response | Triage, investigation, containment, remediation, communication and post-incident action. |
Privacy | Processor controls, personal-data breach notification and lawful international-transfer mechanisms. |
AI / models | Controlled model access; approved enterprise/private model paths; no APEXE3 training of shared foundation models on client-identifiable content. |
Third parties | Due diligence and appropriate data-protection arrangements for providers processing client data. |
Appendix B. Security and trust enquiries
Security & trust | |
Privacy / legal | |
Website | |
Supporting evidence | ISO/IEC 27001 certificate/scope, security questionnaire responses and high-level architecture information may be provided where appropriate. |
