Security and trust

Evaluate the controls.
Agree the commitments.

Start with the documented authorization and recovery model. Then confirm the deployment, data handling, and service requirements for your application with Apexbase LLC.

Documented capabilities

Inspect how access and recovery work.

Each statement below links to its technical documentation. These capabilities do not replace application testing or an agreed service level.

Backend-enforced data access

Entity and property permissions are enforced for the caller during Entity Service data operations.

Read the documentation ↗

Record-level policies

Permission policies can apply query-based record conditions and operation masks through user, role, group, position, and department assignments.

Read the documentation ↗

Property-level permissions

Entity definitions support default property permissions and per-property overrides enforced during backend data operations.

Read the documentation ↗

Permission-scoped agent tools

Supported console operations are available to authorized agents through permission-scoped tools.

Read the documentation ↗

Workspace restore points

Workspace backups distinguish automatic and manual restore points; authorized operators can create on-demand backups and restore completed snapshots.

Read the documentation ↗

Record history and snapshots

Version-enabled entities support explicit restorable snapshots, while tracked entities retain automatic field-change history.

Read the documentation ↗

Automatic backup availability and retention depend on the workspace plan. On-demand backups require the appropriate plan and permissions. Check that a backup completed before relying on it, and validate the application after a restore. A source revert does not restore runtime data.

Your application’s security responsibilities

You define and test permissions, protect credentials, configure integrations, and decide which tools can act on your workspace. Backend enforcement applies those permissions; it does not decide whether your policy is appropriate. Review and test AI-generated changes before deployment, and grant agents only the access they need.

Review authentication and workspace access, the static frontend architecture, and the Terms of Service.

Confirm before production

Service-level, security, data-residency, support, and compliance commitments are binding only when expressly stated in a written agreement signed by Apexbase LLC. A plan listing an SLA does not by itself specify an uptime target, recovery time, or service credit.

RequirementWhat to agree for your deployment
Availability and supportSLA scope, availability targets, exclusions, maintenance, support coverage, incident communication, and remedies.
RecoveryBackup frequency, retention, restore coverage, and recovery-time and recovery-point requirements. Record snapshots and workspace restores serve different purposes.
Identity and deploymentSSO and directory integration requirements, workspace isolation, and any private, dedicated, or self-hosted deployment requirements.
Data handlingHosting region, data residency, encryption and key handling, retention and deletion, subprocessors, and whether a data processing agreement is required.
Assurance evidenceRequest the evidence needed for your review. This page does not assert a certification, independent audit result, or compliance guarantee.

Do not submit regulated information unless the relevant service and a written agreement expressly support it. Beta and preview features are not for production workloads or regulated data unless a written agreement says otherwise. See the Terms and Privacy Policy for the governing conditions.

Report a concern or request information

Use our security and legal contact for questions or to arrange a review. For suspected compromise or a security incident, follow the notification contact in the Terms of Service. Do not send passwords, tokens, or customer records in an initial message; request a suitable channel for sensitive details.