# Apertis Trust Center

Security, privacy, and vendor assurance

Apertis is operated by Stima AI, LLC. (Wyoming, USA) and is the control plane for routing AI requests across the providers you select. We protect the application layer, clearly disclose subprocessors, and distinguish Apertis controls from the certifications maintained by our infrastructure and model providers.

For HIPAA-regulated workloads, our Verbatim product line operates under Business Associate Agreements with Google Cloud Platform, Google Workspace, and Amazon Web Services (all signed 2026-05-19). Contact [security@apertis.ai](mailto:security@apertis.ai) to request a countersigned BAA.

Apertis controls tracked: 45
Listed subprocessors: 11
Independent audits: In progress

### Apertis controls the routing layer

We secure the API gateway, account access, provider key handling, request routing, usage records, and customer-facing deletion workflows.

### Provider assurance stays clearly attributed

Cloud, payment, identity, and model providers maintain their own security programs. Their certifications apply to the relevant provider services, not to Apertis as an independent audit claim.

### No customer data is used to train Apertis models

Apertis is not a foundation model trainer. Requests are routed to the providers you choose, and API content is retained only for the periods listed below.

## Responsibility model

This is the important distinction behind any cloud-backed trust claim: provider certifications help us inherit strong infrastructure controls, while Apertis remains responsible for the product controls we build and operate.

### What we operate

Apertis application controls. Authentication, team access, API key encryption, provider routing, usage logs, retention/deletion workflows, vendor review, and incident response.

### What vendors operate

Subprocessor controls. Cloud infrastructure, edge protection, payment processing, database hosting, and selected model inference services under each provider security program.

### What is in progress

Audit posture. SOC 1 and SOC 2 are in progress. Until an independent report is issued, we describe vendor certifications as vendor certifications only.

## Apertis posture

- GDPR: Self-assessed

- CCPA: Self-assessed

- SOC 1: In Progress

- SOC 2: In Progress

- DPA: Available

- HIPAA BAA: Verbatim only

- MFA Supported: Available

- [Privacy Policy](/privacy)
- [Terms of Service](/terms)
- [Request DPA / HIPAA BAA](/trust/dpa)

Vendor certifications apply to the provider service they cover. They do not imply that Apertis is independently SOC 2, ISO, or FedRAMP certified before our own audit is complete.

## Data Handling

| Data Type | Retention | Details |
| --- | --- | --- |
| Prompt & Response Content | 30 days | Automatically deleted. Never used for training. |
| API Usage Logs | 12 months | PII anonymized after 12 months. Statistical data retained for billing. |
| Account Data | Until deletion | Immediately removed via cascade deletion when you delete your account. |
| Payment Records | Per tax law | Processed and retained by Stripe under their own privacy policy. |

## Runtime protection

The controls below focus on the path your request takes through Apertis before it reaches a selected provider.

### Encrypted secrets

Provider keys and sensitive configuration are encrypted at rest, access-controlled, and excluded from source control.

### Account access controls

API access is authenticated, administrative access is restricted, and MFA support is available for account protection.

### Bounded retention

Prompt and response content is retained for 30 days and is not used to train Apertis models.

## Resources

- [Privacy Policy](/privacy)
- [Terms of Service](/terms)
- [Data Processing Agreement / HIPAA BAA](/trust/dpa)
- [Security Overview](mailto:hi@apertis.ai?subject=Security Overview Request)

## Controls

### Asset management

- Technology asset inventory
- TOTP-based two-factor authentication for admin accounts

### Business continuity and disaster recovery

- Hourly off-site database backups to Google Cloud Storage (3-day retention)
- Business continuity plan

### Change management

- Material system change communication
- Version-controlled deployments

### Cloud security

- Cloud provider physical access review
- Infrastructure-as-code configuration

### Configuration management

- Baseline configuration management
- Environment variables encrypted at rest

### Continuous monitoring

- Centralized log collection and monitoring
- Scheduled weekly automated security scans

### Cryptographic protections

- AES-256-GCM encryption for API keys at rest
- TLS/HTTPS encryption for all data in transit
- Production key management
- Password hashing with bcrypt + PBKDF2-SHA256

### Data classification and handling

- Data classification and access control
- Data retention and deletion policy
- Customer data deletion on request
- API request data never used for model training

### Endpoint security

- Anti-malware protection

### Identification and authentication

- Role-based access control (RBAC)
- JWT authentication for all API endpoints
- Password policy enforcement
- Multi-factor authentication support

### Incident response

- Incident response procedures
- Security incident logging
- Security concern resolution process

### Network security

- DDoS protection via Cloudflare
- Web application firewall
- Network firewall rules
- Docker network isolation for internal services

### Secure engineering and architecture

- Source code access controls
- Secure development procedures
- Environment separation (dev/staging/prod)
- Static application security testing

### Third-party management

- Vendor management program
- Contractual security commitments
- Vendor confidentiality and privacy agreements

### Vulnerability and patch management

- Patch management
- Vulnerability scanning and remediation
- Dependency security monitoring

### Payment security

- PCI DSS Level 1 payment processing (Stripe)
- No credit card data stored on our servers
- Tokenized payment methods

## Subprocessors

API requests are routed only to providers whose models you explicitly select.

| Provider | Purpose | Location | Assurance basis |
| --- | --- | --- | --- |
| OpenAI | AI model inference | US | Provider API security program |
| Anthropic | AI model inference | US | Provider API security program |
| Google | AI model inference (Gemini / Vertex AI) | US | Google Cloud compliance program |
| AWS | AI model inference (Bedrock) | US | AWS compliance program |
| Microsoft Azure | AI model inference | US | Azure compliance program |
| Alibaba Cloud | AI model inference | SG | Alibaba Cloud security program |
| Cohere | AI model inference | CA | Provider API security program |
| Cloudflare | CDN, DNS, security, Workers AI | Global | Cloudflare compliance program |
| Google Cloud | Infrastructure hosting | US | Google Cloud compliance program |
| Supabase | Database hosting | US | Supabase security program |
| Stripe | Payment processing | US | PCI DSS Level 1 service provider |

## Questions about security or compliance?

For security inquiries, DPA requests, or data subject access requests. We can also provide a more detailed security overview for enterprise review.

[hi@apertis.ai](mailto:hi@apertis.ai)

Phone: +1 814-731-3793

Last updated: May 9, 2026 · Stima AI, LLC.
