Apteco security overview
The Apteco security overview explains Apteco's security practices and how Apteco protects your data. This overview aims to give you confidence that your data is secure with Apteco. It also demonstrates Apteco's commitment to maintaining a secure and trustworthy environment.
Internet-connected systems offer many benefits, such as location independence, wide access, and sharing, but they also have vulnerabilities. Apteco software includes many features that can increase security and protect the data in your system.
Note
Many of the security features detailed here are subject to configuration controls. The security of a database depends on the precise configuration deployed for that database. Security threats evolve, and systems therefore require ongoing monitoring to maintain standards.
- Architecture security: web service security features and database data protection
- Securing your system: practical steps to increase the security of your Apteco installation
Client confidentiality and Apteco employment contracts¶
Apteco employee contracts include clauses requiring employees to maintain client confidentiality.
Secure software development lifecycle¶
Apteco follows best practices as part of its software development lifecycle, including:
- Annual in-depth dedicated penetration testing by independent security consultants
- Software Composition Analysis (SCA) scans of third-party source code libraries
- Static Application Security Testing (SAST) scans of source code
- Code reviews of all feature developments performed by skilled and knowledgeable developers
- Antivirus software running on all user systems, and on all builds of Apteco software
- Vulnerability scans, such as Payment Card Industry (PCI) scans, run daily on a deployed system
- Security configuration and endpoint vulnerability continuous scanning of all user systems