Skip to content
Security, privacy, and vendor assurance

Apertis Trust Center

Apertis is operated by Stima AI, LLC. (Wyoming, USA) and is the control plane for routing AI requests across the providers you select. We protect the application layer, clearly disclose subprocessors, and distinguish Apertis controls from the certifications maintained by our infrastructure and model providers.

For HIPAA-regulated workloads, our Verbatim product line operates under Business Associate Agreements with Google Cloud Platform, Google Workspace, and Amazon Web Services (all signed 2026-05-19). Contact security@apertis.ai to request a countersigned BAA.

hi@apertis.ai

Phone: +1 814-731-3793

Apertis controls tracked45
Listed subprocessors11
Independent auditsIn progress

Apertis controls the routing layer

We secure the API gateway, account access, provider key handling, request routing, usage records, and customer-facing deletion workflows.

Provider assurance stays clearly attributed

Cloud, payment, identity, and model providers maintain their own security programs. Their certifications apply to the relevant provider services, not to Apertis as an independent audit claim.

No customer data is used to train Apertis models

Apertis is not a foundation model trainer. Requests are routed to the providers you choose, and API content is retained only for the periods listed below.

Responsibility model

This is the important distinction behind any cloud-backed trust claim: provider certifications help us inherit strong infrastructure controls, while Apertis remains responsible for the product controls we build and operate.

Apertis application controls

What we operate

Authentication, team access, API key encryption, provider routing, usage logs, retention/deletion workflows, vendor review, and incident response.

Subprocessor controls

What vendors operate

Cloud infrastructure, edge protection, payment processing, database hosting, and selected model inference services under each provider security program.

Audit posture

What is in progress

SOC 1 and SOC 2 are in progress. Until an independent report is issued, we describe vendor certifications as vendor certifications only.

Apertis posture

GDPR

GDPR

Self-assessed
CCPA

CCPA

Self-assessed
SOC 1

SOC 1

In Progress
SOC 2

SOC 2

In Progress
DPA

DPA

Available
HIPAA

HIPAA BAA

Verbatim only
MFA

MFA Supported

Available

Vendor certifications apply to the provider service they cover. They do not imply that Apertis is independently SOC 2, ISO, or FedRAMP certified before our own audit is complete.

Data Handling

Data TypeRetentionDetails
Prompt & Response Content30 daysAutomatically deleted. Never used for training.
API Usage Logs12 monthsPII anonymized after 12 months. Statistical data retained for billing.
Account DataUntil deletionImmediately removed via cascade deletion when you delete your account.
Payment RecordsPer tax lawProcessed and retained by Stripe under their own privacy policy.

Runtime protection

The controls below focus on the path your request takes through Apertis before it reaches a selected provider.

Encrypted secrets

Provider keys and sensitive configuration are encrypted at rest, access-controlled, and excluded from source control.

Account access controls

API access is authenticated, administrative access is restricted, and MFA support is available for account protection.

Bounded retention

Prompt and response content is retained for 30 days and is not used to train Apertis models.

Resources

Privacy Policy
View
Terms of Service
View
Data Processing Agreement / HIPAA BAA
Request
Security Overview
Request

Controls

45 controls
Asset management2
  • Technology asset inventory
  • TOTP-based two-factor authentication for admin accounts
Business continuity and disaster recovery2
  • Hourly off-site database backups to Google Cloud Storage (3-day retention)
  • Business continuity plan
Change management2
  • Material system change communication
  • Version-controlled deployments
Cloud security2
  • Cloud provider physical access review
  • Infrastructure-as-code configuration
Configuration management2
  • Baseline configuration management
  • Environment variables encrypted at rest
Continuous monitoring2
  • Centralized log collection and monitoring
  • Scheduled weekly automated security scans
Cryptographic protections4
  • AES-256-GCM encryption for API keys at rest
  • TLS/HTTPS encryption for all data in transit
  • Production key management
  • Password hashing with bcrypt + PBKDF2-SHA256
Data classification and handling4
  • Data classification and access control
  • Data retention and deletion policy
  • Customer data deletion on request
  • API request data never used for model training
Endpoint security1
  • Anti-malware protection
Identification and authentication4
  • Role-based access control (RBAC)
  • JWT authentication for all API endpoints
  • Password policy enforcement
  • Multi-factor authentication support
Incident response3
  • Incident response procedures
  • Security incident logging
  • Security concern resolution process
Network security4
  • DDoS protection via Cloudflare
  • Web application firewall
  • Network firewall rules
  • Docker network isolation for internal services
Secure engineering and architecture4
  • Source code access controls
  • Secure development procedures
  • Environment separation (dev/staging/prod)
  • Static application security testing
Third-party management3
  • Vendor management program
  • Contractual security commitments
  • Vendor confidentiality and privacy agreements
Vulnerability and patch management3
  • Patch management
  • Vulnerability scanning and remediation
  • Dependency security monitoring
Payment security3
  • PCI DSS Level 1 payment processing (Stripe)
  • No credit card data stored on our servers
  • Tokenized payment methods

Subprocessors

API requests are routed only to providers whose models you explicitly select.

11 providers
ProviderPurposeLocationAssurance basis
OpenAIAI model inferenceUSProvider API security program
AnthropicAI model inferenceUSProvider API security program
GoogleAI model inference (Gemini / Vertex AI)USGoogle Cloud compliance program
AWSAI model inference (Bedrock)USAWS compliance program
Microsoft AzureAI model inferenceUSAzure compliance program
Alibaba CloudAI model inferenceSGAlibaba Cloud security program
CohereAI model inferenceCAProvider API security program
CloudflareCDN, DNS, security, Workers AIGlobalCloudflare compliance program
Google CloudInfrastructure hostingUSGoogle Cloud compliance program
SupabaseDatabase hostingUSSupabase security program
StripePayment processingUSPCI DSS Level 1 service provider

Questions about security or compliance?

For security inquiries, DPA requests, or data subject access requests. We can also provide a more detailed security overview for enterprise review.

hi@apertis.ai

Last updated: May 9, 2026 · Stima AI, LLC.