Independently audited

Trust Center

Apex protects construction's most sensitive financial data. Here's the proof — certifications, controls, sub-processors, and downloadable artifacts your security team needs.

Certifications & Frameworks

All certifications independently audited and renewed on schedule.

SOC 2 Type II

Active

Audited annually by independent CPA firm. Covers Security, Availability, Confidentiality.

ISO 27001:2022

Active

Information security management system certification. Re-audited every 3 years.

GDPR

Compliant

EU data residency, Data Processing Agreement, Right to Erasure, breach notification.

CCPA / CPRA

Compliant

California Consumer Privacy Act. Do-not-sell controls and verified deletion requests.

HIPAA

Available

Business Associate Agreement available for healthcare GCs on Enterprise plan.

PCI DSS

Compliant

All payment data handled by Stripe (Level 1 PCI service provider). Apex never sees card data.

Security Controls

Defense in depth across infrastructure, application, and identity.

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Field-level encryption for SSN, EIN, bank routing & account numbers.

MFA + Passkeys

TOTP, WebAuthn / FIDO2 passkeys, and SAML SSO with SCIM provisioning on Enterprise.

Immutable audit log

Every read, write, and admin action recorded. Exportable to CSV or streamed to SIEM via webhook.

99.95% uptime SLA

Multi-AZ deployment, automated failover, RPO < 5 min, RTO < 1 hour. Quarterly DR exercises.

Data residency

Choose US or EU at workspace creation. Data never crosses the boundary you select.

Tenant isolation

Logical isolation enforced by Row-Level Security policies on every table. Dedicated DB available on Enterprise.

Sub-processors

Vendors that process customer data on our behalf. Notification 30 days before any addition.

VendorPurposeRegion
Amazon Web ServicesPrimary cloud infrastructureUS-East / EU-West
SupabaseManaged PostgreSQL + AuthUS / EU multi-region
StripePayment processingUS, PCI Level 1
CloudflareCDN, DDoS, WAFGlobal edge
SentryError monitoringUS-West
OpenAI / Google AILLM inference (opt-in)US, zero-retention

Documents & Reports

Available under NDA to qualified prospects. Sign in or contact us for instant access.

SOC 2 Type II Report

PDF · 4.2 MB · Under NDA

ISO 27001 Certificate

PDF · 380 KB

Penetration Test Summary

PDF · 1.1 MB · Under NDA

Data Processing Agreement

PDF · 220 KB

Business Continuity Plan

PDF · 680 KB · Under NDA

Standard Security Questionnaire (CAIQ-Lite)

XLSX · 95 KB

99.95% Uptime SLA

Service credits applied automatically if monthly uptime falls below targets. Real-time status published at status.billslash.com. Incident post-mortems published within 5 business days.

View live status →