Security Addendum
This Security Addendum is part of the Agreement between Apilex and the Customer, and is incorporated by reference into the DPA. Capitalized terms not defined in this Addendum have the meaning given to them in the DPA.
1. Audits and Certifications
1.1 Apilex's information security management system is certified under ISO/IEC 27001:2022 (Certificate No. 2026/ISMS/002348, issued by IQR International Certification Services LLC, an IAF/IAS-accredited certification body (MSCB-135); initial certification date: 9 April 2026; valid through 8 April 2027).
1.2 Upon the Customer's request, Apilex shall make available a copy of its current ISO 27001 certificate and statement of applicability, as further described in Section 10.
1.3 If Apilex discontinues this certification, it shall adopt an equivalent, industry-recognized framework and shall inform the Customer of the change.
2. Hosting Location of Content
2.1 Content is hosted in data centers located within the region specified in the Sub-Processor List. For customers in Türkiye, Content is hosted on domestic cloud infrastructure within Türkiye, in case of a request. For EEA customers, Content is hosted within the EEA.
2.2 Any sub-processor that processes Content outside the Customer's designated region does so subject to the transfer safeguards described in the DPA (international data transfers).
3. AI Processing Safeguards
3.1 Apilex's AI model providers operate under a zero-data-retention (ZDR) policy: queries and documents submitted for AI processing are not persistently logged, cached, or stored by the provider after the response is returned.
3.2 No Customer Content is used by any AI model provider for the purpose of training, fine-tuning, or improving its models. This restriction is contractually binding on each provider through a Data Processing Agreement.
3.3 One customer's Content cannot influence the outputs generated for another customer. Each processing request is handled independently within the Customer's authenticated session.
3.4 The current list of AI model providers and their processing locations is maintained in the Sub-Processor List.
4. Encryption
4.1 Content at rest (databases, object storage, and backups) is encrypted using AES-256 (or better).
4.2 Content in transit is encrypted using TLS 1.2 (or better).
4.3 Encryption keys are logically separated from the data they protect and are rotated on a regular, automated basis.
5. System and Network Security
5.1 Access to Content is restricted according to the principle of least privilege, enforced through role-based access control (RBAC).
5.2 Multi-factor authentication is required for critical operations.
5.3 Passwords are hashed using bcrypt and are subject to minimum-length and complexity requirements.
5.4 Access for separated personnel is revoked on the day of separation. Access privileges are reviewed at least quarterly.
5.5 Apilex maintains brute-force protection and logs administrator-level actions.
5.6 Apilex's cloud infrastructure logically isolates each customer's Content through mandatory tenant-scoped query filters applied across its data stores, preventing cross-customer access. Power, cooling, and network components are provisioned with N+1 redundancy, and DDoS protection is provided through Apilex's cloud infrastructure provider.
6. Secure Development
6.1 Security is addressed from the design stage of Apilex's software development lifecycle. All code changes are subject to mandatory peer review.
6.2 Static application security testing (SAST) tools are integrated into the CI/CD pipelines of Apilex's core services, and Apilex is progressively extending this coverage across all repositories. Dependency scanning and patch management are carried out at regular intervals.
6.3 Secrets (such as API keys and passwords) are never embedded in source code and are managed through a centralized secrets management system.
6.4 Apilex does not copy production data into test or development environments.
7. Vendors and Sub-Processors
7.1 Apilex ensures that any sub-processor that processes Content maintains security measures consistent with Apilex's obligations under this Addendum, as further described in the DPA (sub-processor obligations).
7.2 Apilex's current sub-processors, and the safeguards applicable to each, are listed in the Sub-Processor List.
8. Incident Detection and Response
8.1 Apilex monitors its systems in real time through 24/7 monitoring with automated alerting.
8.2 If Apilex becomes aware of a Personal Data Breach affecting Content, it shall notify the Customer without undue delay, and in any event within 72 hours, in accordance with the DPA (breach notification).
8.3 Apilex maintains a documented incident response plan and escalation procedures, and shall take reasonable steps to contain, investigate, and mitigate any Personal Data Breach.
8.4 Critical vulnerabilities identified through penetration testing, vulnerability scanning, or otherwise are remediated within 7 business days of discovery.
9. Audit Logging
9.1 Apilex maintains audit logs sufficient to trace system activity to an individual user.
9.2 Security logs are retained for 5 years.
10. Customer Audit Rights
10.1 Upon request, Apilex shall make available to the Customer a copy of its current ISO 27001 certificate and statement of applicability, together with a summary of its most recently completed penetration test containing, at a minimum: the name of the testing organization, the date of the test, its scope, the testing methodology, and a summary of the findings.
10.2 The Customer may conduct an on-site audit no more than once per calendar year, upon at least 30 days' prior written notice. Apilex's ISO 27001 certification may be accepted as evidence of compliance in lieu of an on-site audit, at the Customer's discretion. Audits shall be carried out in accordance with, and subject to the confidentiality protections set out in, the DPA (audit rights and procedures).
11. Testing and Vulnerability Management
11.1 Apilex engages an independent third party to conduct a penetration test of the Services at least annually.
11.2 Apilex conducts web application security assessments in line with OWASP methodology, and regularly scans against the National Vulnerability Database (NVD) or an equivalent source to identify and prioritize vulnerabilities in the software it uses.
12. Administrative Controls
12.1 Apilex personnel receive security training upon onboarding and at least annually thereafter. Where an urgent security matter arises, Apilex provides additional briefing to relevant personnel.
12.2 Developers receive training on secure coding practices.
12.3 All Apilex personnel and contractors are bound by confidentiality obligations.
12.4 Personnel with access to Content are subject to background and identity verification, to the extent permitted by applicable law.
12.5 Antivirus and data loss prevention (DLP) tools are active on all endpoints.
13. Backup and Business Continuity
13.1 Content is backed up on a regular basis in encrypted form, in accordance with Apilex's backup retention schedule. Backup copies are automatically overwritten at the end of their retention cycle.
13.2 Apilex maintains business continuity and disaster recovery procedures with defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets.
14. Customer Responsibilities
14.1 The Customer is responsible for ensuring that its use of the Services complies with applicable law.
14.2 The Customer is responsible for managing and protecting its credentials to access the Services. Credentials must not be shared with unauthorized parties, and the Customer shall promptly report any suspected compromise.
14.3 The Customer is responsible for keeping the systems it uses to access the Services (for example, its browser) up to date and appropriately patched.