Data Security & Incident Response Commitment

Our Commitment

At Aptora Corporation (“Aptora,” “we,” “our,” or “us”), safeguarding the confidentiality, integrity, and availability of customer information is one of our highest priorities.

Our customers rely on Aptora’s software and hosted services to operate critical aspects of their businesses. We understand the trust placed in us and are committed to maintaining an information security program designed to protect customer data from unauthorized access, disclosure, alteration, destruction, or loss while supporting the reliable delivery of our products and services.

Cybersecurity is an ongoing process. We continually assess risks, evaluate emerging threats, and improve our security practices to strengthen the protection of customer information.

Our Security Principles

Our information security program is guided by the following principles:

  • Protect customer information using appropriate administrative, technical, and physical safeguards.
  • Limit access to information based on business need and the principle of least privilege.
  • Continuously monitor and improve our security posture.
  • Respond promptly and effectively to suspected security incidents.
  • Communicate openly and responsibly with affected customers when notification is required.
  • Comply with applicable legal, contractual, and regulatory obligations.

Information We Protect

Depending on the services selected by our customers, Aptora systems may store or process business information including:

  • Customer and contact information
  • Employee records
  • Vendor information
  • Accounting records
  • Estimates and invoices
  • Work orders
  • Scheduling information
  • Inventory records
  • Service history
  • Payment information
  • Attachments, documents, and images
  • Communications generated through our software
  • Other business information entered by customers

Customers retain ownership of the business information they store within Aptora products and services. Aptora processes customer data solely to provide the products and services requested by our customers.

Administrative Safeguards

Our security program includes administrative controls designed to reduce risk and promote the secure handling of information.

These measures include, as appropriate:

  • Written information security policies and procedures
  • Security awareness and cybersecurity training
  • Employee confidentiality obligations
  • Background screening where appropriate
  • Access approval and review procedures
  • Vendor security assessments
  • Change management practices
  • Risk assessments
  • Business continuity planning
  • Incident response planning

Technical Safeguards

Aptora employs multiple layers of technical safeguards designed to help protect customer information.

These safeguards may include:

  • Role-based access controls
  • Multi-factor authentication where appropriate
  • Network firewalls
  • Endpoint protection
  • Anti-malware technologies
  • Security monitoring
  • Security event logging
  • Secure remote administration
  • Vulnerability scanning
  • Security patch management
  • Encryption technologies
  • Secure authentication mechanisms
  • Backup monitoring
  • Network segmentation where appropriate

Security technologies continue to evolve, and Aptora regularly evaluates and updates its technical controls to address changing risks.

Physical Safeguards

Where applicable, physical safeguards include:

  • Controlled access to facilities
  • Visitor management procedures
  • Secure disposal of media and equipment
  • Environmental protections
  • Physical security controls maintained by trusted hosting providers and data centers

Access Controls

Access to customer information is limited to authorized personnel who require access to perform legitimate business functions.

Access is managed through:

  • Unique user accounts
  • Role-based permissions
  • Least privilege principles
  • Authentication controls
  • Administrative approval processes  
  • Periodic access reviews
  • Timely removal of access when no longer required

Encryption

Aptora uses industry-standard encryption technologies to help protect sensitive information during transmission across public networks.

Where appropriate, sensitive authentication credentials, access tokens, and other confidential information are encrypted while stored.

Security Monitoring

To help identify potential threats, Aptora may monitor systems for:

  • Unauthorized access attempts
  • Failed authentication events
  • Privileged account activity
  • Malware detection
  • Suspicious network activity
  • Security alerts
  • Operational anomalies

Security monitoring assists in identifying, investigating, and responding to potential security events.

Vulnerability Management

Maintaining secure systems requires continuous attention.

Our vulnerability management program includes activities such as:

  • Routine software updates
  • Security patch deployment
  • Configuration reviews
  • Vulnerability assessments
  • Risk evaluations
  • Remediation of identified security issues based upon risk and operational impact

Backup, Recovery, and Business Continuity

Business continuity is an important component of our security program.

Aptora maintains backup and recovery processes designed to support the restoration of critical services following operational interruptions.

These processes may include:

  • Scheduled backups
  • Backup integrity verification
  • Disaster recovery planning
  • Recovery testing
  • Infrastructure redundancy where appropriate

Employee Security Awareness

Our employees play an important role in protecting customer information.

Personnel receive security awareness training covering topics such as:

  • Password security
  • Phishing awareness
  • Social engineering
  • Secure handling of confidential information
  • Incident reporting procedures
  • Acceptable use of company systems  

Third-Party Service Providers

Aptora may engage trusted third-party providers to support services such as cloud hosting, communications, payment processing, monitoring, and infrastructure.

Where appropriate, we require service providers to maintain reasonable administrative, technical, and physical safeguards designed to protect customer information consistent with their contractual obligations.

Customer Responsibilities

Information security is a shared responsibility.

Customers can help protect their information by:

  • Maintaining strong passwords
  • Enabling multi-factor authentication where available
  • Restricting user access based on job responsibilities
  • Promptly applying software updates
  • Protecting endpoint devices
  • Reviewing user accounts periodically
  • Promptly reporting suspected security concerns to Aptora

Our Incident Response Commitment

Aptora maintains documented procedures for responding to suspected or confirmed information security incidents.

When a security event is identified, our response is designed to:

  1. Detect and validate the event.
  2. Contain unauthorized activity to reduce potential impact.
  3. Preserve relevant evidence where appropriate.
  4. Investigate the nature, scope, and potential impact of the incident.
  5. Eradicate malicious activity and remediate identified vulnerabilities.
  6. Restore affected systems and services in a controlled manner.
  7. Coordinate with internal teams, cybersecurity professionals, legal counsel, cyber insurance representatives, and law enforcement when appropriate.
  8. Review the incident and implement corrective actions to strengthen our security posture.

Customer Notification Commitment

If Aptora determines that customer information has been accessed, acquired, or disclosed without authorization and notification is required under applicable law or contractual obligation, we are committed to notifying affected customers without unreasonable delay following an appropriate investigation.

Our notifications will generally include:

  • A summary of the incident.
  • The categories of information believed to be involved.
  • The actions Aptora has taken to investigate and respond.
  • Recommended actions customers may consider.
  • Contact information for additional assistance.
  • Updates as additional information becomes available, when appropriate.

Cooperation with Authorities

When appropriate, Aptora may coordinate with:

  • Federal law enforcement agencies
  • State regulatory authorities
  • Privacy regulators
  • Cybersecurity experts
  • Legal counsel
  • Cyber insurance providers

to support the investigation and response to significant security incidents.

Continuous Improvement

Security is not a one-time effort but an ongoing commitment.

Following significant security events, Aptora reviews its security controls, technologies, policies, procedures, and training programs to identify opportunities for improvement and to strengthen our overall security posture.

Responsible Disclosure

We encourage responsible reporting of suspected security vulnerabilities.

Individuals who believe they have identified a security vulnerability are encouraged to report it in accordance with our Responsible Disclosure Policy.

Reports may be submitted to:

Email: helpdesk@aptora.com

Contact Us

Questions regarding this Data Security & Incident Response Commitment or our security practices may be directed to:

Aptora Corporation
Attn: Information Security Officer
8877 Bourgade Avenue
Lenexa, Kansas 66219
United States

Email: helpdesk@aptora.com

Phone: (913) 492-9930