Your data, your workspace, your exit.
This page is written for whoever has to approve Aptic - a partner, a board, a client of yours, or your own caution. It says what we do, what we do not do, and what you can hold us to.
Four commitments, in plain language.
Your workspace is yours alone
Every client runs in a separate workspace. Your data is not pooled with another client’s, and nothing from your business is visible to another business using Aptic.
We do not sell or share your data
Your data is used to serve you. It is not sold, shared, or repackaged.
Read by default, write only where you allow it
Connecting a system does not authorise Aptic to change it. Write access is granted separately, for specific kinds of action, and several connections cannot write at all.
You can leave with everything
Your data is exportable for as long as you are a client, and deleted on request when you stop being one.
What a connection actually grants.
Connecting a tool is the point at which most people stop reading a security page. It is also the point that matters most, so here is the detail.
- Aptic asks for the narrowest access that lets it do the job, and tells you what a connection will read before you approve it.
- Credentials are encrypted at rest and are never displayed back to anyone, including us.
- You can revoke any connection at any time, from your side or ours. Revoking it stops the work that depended on it rather than quietly degrading it.
- Several connections, financial ones included, cannot write at all. Finance is advisory and does not move money.
Who inside Aptic can see your business.
Access inside Aptic is granted by role and by need, expires on its own where it was granted temporarily, and is recorded. A consultant assigned to your account can see your account. Nobody browses.
- Access is scoped to the people actually working on your engagement
- Elevated access is time-boxed and expires without anyone having to remember to remove it
- Every grant is recorded and reviewable
- Support access to your workspace requires a stated reason, and you can ask us for the log
Everything consequential is written down.
Every action Aptic takes on your behalf, every approval, and every outcome is recorded permanently: who decided it, when, on what evidence, and what came back. That record exists for your benefit first. It is what makes an AI working inside your business auditable rather than merely fast.
How governance worksWhat happens to your data over time.
While you are a client
Your data is retained so Aptic can compare periods, measure outcomes, and get better at advising you specifically. History is what makes the advice improve.
Export
Your business data, decisions, and reports are exportable in standard formats whenever you want them.
On exit
Connections are revoked and your workspace data is deleted on request, subject only to records we are legally required to keep.
If you find a problem, tell us.
If you believe you have found a security issue, contact us before disclosing it publicly. We will acknowledge it, investigate, and tell you what we found. We do not pursue people who report issues to us in good faith.
Contact usBring us your requirements.
If you have a security questionnaire, a procurement process, or a client of your own whose rules you have to satisfy, send it over and we will work through it.