Security
What Apsio does to keep your data apart and safe, said plainly. This page will grow as the service does.
Stored in US East
During early access, everything is stored in one region, US East: the application servers, the telemetry store and object storage. The EU comes next, when the first customer needs it.
Tenants kept apart by the database
Each organization reads the telemetry store as its own database user, limited by row policies to its own data. A query from one tenant cannot return another tenant's rows, even if the application code is wrong.
Less data to protect
Redaction runs on the device, before anything is sent. Replay draws the layout, never the pixels, with text masked by default. No IP address is stored, and no advertising or vendor identifier is collected.
Payments and sign-in
Card details go straight to Stripe and never reach Apsio's servers. Sign-in runs through WorkOS, with SSO and SCIM on Enterprise.
Agents
Agents act with the permissions of the person who connected them, read-only by default, and every call is in the audit log.
Reporting a vulnerability
Write to hello@apsio.io. A person replies. [Disclosure policy and response times to be published.]