Legal

Security

How Apture Labs secures the platform, and what a customer is responsible for inside their own environment.

Last updated · Draft
Draft · not legal advice

This document is a structural scaffold. Each section describes what belongs in it; none of it is operative legal language, and it has not been reviewed by a lawyer. Replace the body text with counsel-approved wording before relying on this page.

Shared responsibility

Where Apture’s responsibility ends and the customer’s begins. For on-prem this line sits further toward the customer than for typical SaaS — set the expectation early.

Deployment models

The security properties of on-prem, edge, and private cloud, including what network egress each requires.

Access control

Authentication, SSO support, roles and permissions, the agent permission grammar, and how a violating agent is quarantined.

Encryption

In transit and at rest, with the algorithms and key management actually used.

Human-in-the-loop and approvals

The sign-off queue, reversible versus irreversible action classification, and the append-only audit log — these are security controls, not just features.

Secure development

Code review, dependency scanning, secrets handling, and the release process.

Infrastructure and hardening

Host hardening, patching cadence, and network segmentation guidance.

Monitoring and incident response

Detection, the incident response process, and the notification commitment and timeline.

Business continuity

Backup, recovery objectives, and what a customer should run themselves.

Compliance

Current posture and any certifications in progress. Do not claim a certification that is not held.

Reporting a vulnerability

How to report, what to expect, and the safe-harbour commitment. security@apturelabs.com.