Information Security Policy
- Effective Date: August 5, 2026
- Last updated: August 6, 2026
Purpose
Aptora Corporation is committed to protecting the confidentiality, integrity, and availability of customer, employee, and company information.
This Information Security Policy outlines the safeguards we maintain to protect information systems and data against unauthorized access, disclosure, alteration, destruction, or interruption.
Scope
This policy applies to:
- All Aptora employees
- Contractors
- Consultants
- Temporary personnel
- Third parties with authorized access
- Cloud-hosted services
- Corporate networks
- Customer-hosted environments supported by Aptora
- All information processed by Aptora systems
Information Security Program
Aptora maintains a comprehensive information security program designed to:
- Protect confidential information
- Maintain service availability
- Preserve data integrity
- Reduce cybersecurity risks
- Meet contractual obligations
- Support business continuity
- Comply with applicable legal and regulatory requirements
Administrative Safeguards
Our security program includes administrative controls such as:
- Written security policies
- Employee confidentiality agreements
- Security awareness training
- Acceptable use standards
- Background screening where appropriate
- Vendor due diligence
- Risk assessments
- Change management
- Access approval procedures
- Incident response planning
- Business continuity planning
Access Management
Access to systems and information is granted based upon business necessity and follows the principle of least privilege.
Access controls include:
- Individual user accounts
- Role-based permissions
- Password standards
- Multi-factor authentication where supported
- Periodic review of user permissions
- Prompt removal of access following employment changes
- Administrative access restrictions
Authentication
To help protect customer information, Aptora utilizes authentication controls that may include:
- Strong password requirements
- Account lockout protections
- Multi-factor authentication
- Secure session management
- Encrypted authentication credentials
Network Security
Network protections may include:
- Firewalls
- Secure remote access
- Network segmentation
- Security monitoring
- Traffic filtering
- Intrusion detection technologies
- Endpoint protection
Encryption
Sensitive information is protected using industry-standard encryption technologies where appropriate.
Encryption may be used for:
- Data transmitted across public networks
- Authentication credentials
- Access tokens
- Sensitive stored information
- Backup media where appropriate
Vulnerability Management
Aptora continuously works to improve security through:
- Security patch management
- Software updates
- Vulnerability scanning
- Configuration reviews
- Risk analysis
- Remediation of identified vulnerabilities
Critical issues are prioritized according to risk.
Monitoring
Systems may be monitored to identify:
- Unauthorized access attempts
- Privileged account activity
- Malware
- Suspicious authentication events
- System anomalies
- Security alerts
- Operational issues
Monitoring supports both operational reliability and incident response.
Backup and Recovery
To support business continuity, Aptora maintains backup and recovery processes designed to:
- Protect customer information
- Restore systems following operational interruptions
- Verify backup integrity
- Support disaster recovery
Recovery procedures are periodically reviewed and tested.
Physical Security
Physical safeguards may include:
- Controlled facility access
- Visitor management
- Environmental protections
- Secure equipment disposal
- Secure hosting facilities operated by trusted providers
Vendor Security
Where appropriate, Aptora evaluates vendors that process customer information or support critical business operations.
Service providers are expected to maintain reasonable administrative, technical, and physical safeguards consistent with applicable contractual obligations.
Employee Responsibilities
Employees are expected to:
- Protect confidential information
- Use company systems responsibly
- Follow established security policies
- Report suspected security incidents immediately
- Complete required security training
- Protect authentication credentials
- Maintain secure work environments Â
Incident Response
Aptora maintains documented procedures for responding to information security incidents.
Our response process includes:
- Identification
- Investigation
- Containment
- Eradication
- Recovery
- Customer communication where appropriate
- Regulatory notification when required
- Lessons learned and continuous improvement
Security Reviews
Our information security program is periodically reviewed to address:
- Emerging cybersecurity threats
- Changes in technology
- Customer requirements
- Business operations
- Regulatory obligations
Security controls are updated as appropriate to maintain an effective security posture.
Policy Updates
This Information Security Policy may be revised periodically to reflect changes in technology, business practices, or applicable legal requirements.
The most current version will be available on our website.
Contact Information
Questions regarding this Information Security Policy may be directed to:
Aptora Corporation
Attention: Information Security Officer
8877 Bourgade Avenue
Lenexa, Kansas 66219
Email: helpdesk@aptora.com
Phone: (913) 492-9930

