Backend-enforced data access
Entity and property permissions are enforced for the caller during Entity Service data operations.
Read the documentation ↗Security and trust
Start with the documented authorization and recovery model. Then confirm the deployment, data handling, and service requirements for your application with Apexbase LLC.
Documented capabilities
Each statement below links to its technical documentation. These capabilities do not replace application testing or an agreed service level.
Entity and property permissions are enforced for the caller during Entity Service data operations.
Read the documentation ↗Permission policies can apply query-based record conditions and operation masks through user, role, group, position, and department assignments.
Read the documentation ↗Entity definitions support default property permissions and per-property overrides enforced during backend data operations.
Read the documentation ↗Supported console operations are available to authorized agents through permission-scoped tools.
Read the documentation ↗Workspace backups distinguish automatic and manual restore points; authorized operators can create on-demand backups and restore completed snapshots.
Read the documentation ↗Version-enabled entities support explicit restorable snapshots, while tracked entities retain automatic field-change history.
Read the documentation ↗Automatic backup availability and retention depend on the workspace plan. On-demand backups require the appropriate plan and permissions. Check that a backup completed before relying on it, and validate the application after a restore. A source revert does not restore runtime data.
You define and test permissions, protect credentials, configure integrations, and decide which tools can act on your workspace. Backend enforcement applies those permissions; it does not decide whether your policy is appropriate. Review and test AI-generated changes before deployment, and grant agents only the access they need.
Review authentication and workspace access, the static frontend architecture, and the Terms of Service.
Service-level, security, data-residency, support, and compliance commitments are binding only when expressly stated in a written agreement signed by Apexbase LLC. A plan listing an SLA does not by itself specify an uptime target, recovery time, or service credit.
| Requirement | What to agree for your deployment |
|---|---|
| Availability and support | SLA scope, availability targets, exclusions, maintenance, support coverage, incident communication, and remedies. |
| Recovery | Backup frequency, retention, restore coverage, and recovery-time and recovery-point requirements. Record snapshots and workspace restores serve different purposes. |
| Identity and deployment | SSO and directory integration requirements, workspace isolation, and any private, dedicated, or self-hosted deployment requirements. |
| Data handling | Hosting region, data residency, encryption and key handling, retention and deletion, subprocessors, and whether a data processing agreement is required. |
| Assurance evidence | Request the evidence needed for your review. This page does not assert a certification, independent audit result, or compliance guarantee. |
Do not submit regulated information unless the relevant service and a written agreement expressly support it. Beta and preview features are not for production workloads or regulated data unless a written agreement says otherwise. See the Terms and Privacy Policy for the governing conditions.
Use our security and legal contact for questions or to arrange a review. For suspected compromise or a security incident, follow the notification contact in the Terms of Service. Do not send passwords, tokens, or customer records in an initial message; request a suitable channel for sensitive details.