Apptad is entrusted with sensitive customer data on every engagement. This page summarizes our information security program at a high level. For details specific to your engagement (control matrices, audit reports, contractual security commitments), contact your Apptad relationship lead or security@apptadinc.com.
1. Governance
Apptad maintains an information security program led by senior leadership and reviewed at least annually. Policies cover risk management, access control, secure development, incident response, vendor risk, business continuity, and personnel security. Employees and contractors complete onboarding and annual refresher training on security and data-handling expectations.
2. Frameworks & certifications
Our program is aligned with industry-recognized frameworks. Specific certifications and reports applicable to a given service may include SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27701, HIPAA, and others, and will be confirmed in the relevant engagement documentation. Customers under NDA may request the latest reports from security@apptadinc.com.
3. Access control
- Role-based access with least-privilege defaults.
- Multi-factor authentication required for production-system and customer-environment access.
- Quarterly access reviews and timely deprovisioning when employees or contractors change roles.
- Centralized identity and single sign-on for internal systems.
4. Encryption
- Data in transit protected with TLS 1.2 or higher across our public-facing endpoints.
- Data at rest in our managed infrastructure encrypted using industry-standard algorithms.
- Customer-managed encryption supported on engagements where required.
5. Secure development
- Code review and approval workflows for all changes to production systems.
- Static and dependency scanning integrated into CI pipelines.
- Threat modeling for new high-risk services and major architectural changes.
- Periodic penetration testing of customer-facing platforms.
6. Operations & monitoring
- Centralized logging with retention aligned to regulatory and contractual requirements.
- Continuous monitoring for security events with on-call response procedures.
- Defined incident-response playbook with severity tiers, communication plans, and post-incident review.
7. Business continuity & disaster recovery
Apptad maintains documented business-continuity and disaster-recovery plans for the systems and services we operate, including periodic testing of recovery procedures.
8. Vendor risk management
Third-party vendors that handle Apptad or customer data undergo a security and privacy assessment before onboarding and are reviewed periodically thereafter. Contractual obligations require vendors to maintain appropriate safeguards and to notify us of material security events.
9. Reporting a security concern
We welcome reports from security researchers, customers, and the public. To report a vulnerability, suspected compromise, or other security concern:
- Email security@apptadinc.com with as much detail as you can safely provide (steps to reproduce, affected URLs, your assessment of impact).
- Use only non-disruptive testing methods. Do not exfiltrate, modify, or destroy data. Do not pivot to internal systems.
- Provide us a reasonable opportunity to investigate and remediate before any public disclosure.
We will acknowledge receipt within five business days, work in good faith with you on remediation, and publicly credit your contribution if you wish.