Aptus
Security & Privacy

How we protect your data

Last updated: April 2026

Aptus builds and operates managed software products for small and medium businesses. We take the security and privacy of your data seriously. This page describes how we protect the data entrusted to us by our clients and their users.

This page covers client and product data. For how we handle visitors to aptusops.com itself, see our Privacy Policy.

Infrastructure & Hosting

All Aptus products are hosted on enterprise-grade infrastructure operated by providers who maintain SOC 2 Type II certifications. We do not operate our own data centers.

Access Controls

Development Practices

Sub-Processors

Aptus may use the following third-party services to deliver its products. Not every product uses every service — the sub-processors applicable to your product are identified in your Statement of Work.

ServicePurpose
SupabaseDatabase, storage, authentication
VercelHosting, CDN, serverless functions
StripePayment processing
TwilioVoice & SMS (where applicable)
SentryError monitoring
ResendTransactional email
Anthropic / OpenAIAI assistance (chat, content where applicable)

We notify clients before adding new sub-processors. We minimize personal data transmission in all integrations.

Monitoring

Data Handling

Data Retention & Deletion

Upon termination of a client engagement:

Incident Response

In the event of a confirmed security incident affecting client data:

Privacy Compliance

Questions

For security or privacy questions, contact us at nima@aptusops.com.

This document is a summary of Aptus LLC’s security and privacy practices and is reviewed and updated periodically. Client-specific obligations are governed by the Master Service Agreement, applicable Statement of Work, Service Level Agreement, and Data Processing Addendum (where executed).