Information Security Policy

Purpose

Aptora Corporation is committed to protecting the confidentiality, integrity, and availability of customer, employee, and company information.

This Information Security Policy outlines the safeguards we maintain to protect information systems and data against unauthorized access, disclosure, alteration, destruction, or interruption.

Scope

This policy applies to:

  • All Aptora employees
  • Contractors
  • Consultants
  • Temporary personnel
  • Third parties with authorized access
  • Cloud-hosted services
  • Corporate networks
  • Customer-hosted environments supported by Aptora
  • All information processed by Aptora systems

Information Security Program

Aptora maintains a comprehensive information security program designed to:

  • Protect confidential information
  • Maintain service availability
  • Preserve data integrity
  • Reduce cybersecurity risks
  • Meet contractual obligations
  • Support business continuity
  • Comply with applicable legal and regulatory requirements

Administrative Safeguards

Our security program includes administrative controls such as:

  • Written security policies
  • Employee confidentiality agreements
  • Security awareness training
  • Acceptable use standards
  • Background screening where appropriate
  • Vendor due diligence
  • Risk assessments
  • Change management
  • Access approval procedures
  • Incident response planning
  • Business continuity planning

Access Management

Access to systems and information is granted based upon business necessity and follows the principle of least privilege.

Access controls include:

  • Individual user accounts
  • Role-based permissions
  • Password standards
  • Multi-factor authentication where supported
  • Periodic review of user permissions
  • Prompt removal of access following employment changes
  • Administrative access restrictions

Authentication

To help protect customer information, Aptora utilizes authentication controls that may include:

  • Strong password requirements
  • Account lockout protections
  • Multi-factor authentication
  • Secure session management
  • Encrypted authentication credentials

Network Security

Network protections may include:

  • Firewalls
  • Secure remote access
  • Network segmentation
  • Security monitoring
  • Traffic filtering
  • Intrusion detection technologies
  • Endpoint protection

Encryption

Sensitive information is protected using industry-standard encryption technologies where appropriate.

Encryption may be used for:

  • Data transmitted across public networks
  • Authentication credentials
  • Access tokens
  • Sensitive stored information
  • Backup media where appropriate

Vulnerability Management

Aptora continuously works to improve security through:

  • Security patch management
  • Software updates
  • Vulnerability scanning
  • Configuration reviews
  • Risk analysis
  • Remediation of identified vulnerabilities

Critical issues are prioritized according to risk.

Monitoring

Systems may be monitored to identify:

  • Unauthorized access attempts
  • Privileged account activity
  • Malware
  • Suspicious authentication events
  • System anomalies
  • Security alerts
  • Operational issues

Monitoring supports both operational reliability and incident response.

Backup and Recovery

To support business continuity, Aptora maintains backup and recovery processes designed to:

  • Protect customer information
  • Restore systems following operational interruptions
  • Verify backup integrity
  • Support disaster recovery

Recovery procedures are periodically reviewed and tested.

Physical Security

Physical safeguards may include:

  • Controlled facility access
  • Visitor management
  • Environmental protections
  • Secure equipment disposal
  • Secure hosting facilities operated by trusted providers

Vendor Security

Where appropriate, Aptora evaluates vendors that process customer information or support critical business operations.

Service providers are expected to maintain reasonable administrative, technical, and physical safeguards consistent with applicable contractual obligations.

Employee Responsibilities

Employees are expected to:

  • Protect confidential information
  • Use company systems responsibly
  • Follow established security policies
  • Report suspected security incidents immediately
  • Complete required security training
  • Protect authentication credentials
  • Maintain secure work environments  

Incident Response

Aptora maintains documented procedures for responding to information security incidents.

Our response process includes:

  • Identification
  • Investigation
  • Containment
  • Eradication
  • Recovery
  • Customer communication where appropriate
  • Regulatory notification when required
  • Lessons learned and continuous improvement

Security Reviews

Our information security program is periodically reviewed to address:

  • Emerging cybersecurity threats
  • Changes in technology
  • Customer requirements
  • Business operations
  • Regulatory obligations

Security controls are updated as appropriate to maintain an effective security posture.

Policy Updates

This Information Security Policy may be revised periodically to reflect changes in technology, business practices, or applicable legal requirements.

The most current version will be available on our website.

Contact Information

Questions regarding this Information Security Policy may be directed to:

Aptora Corporation
Attention: Information Security Officer
8877 Bourgade Avenue
Lenexa, Kansas 66219

Email: helpdesk@aptora.com

Phone: (913) 492-9930