Security & Trust | TaoApex

Learn how TaoApex documents encryption, access controls, compliance practices, and transparent incident-response procedures for its products and services.

Encryption & Data Protection

All data transmitted between your devices and TaoApex services is protected using TLS 1.3. At rest, data is encrypted with AES-256, the same standard used by governments and financial institutions worldwide.

In Transit

TLS 1.3 with perfect forward secrecy. All API calls, logins, and file transfers are encrypted in transit.

At Rest

encryption controls described in the privacy policy for all stored data, backups, and database snapshots.

Access Control

TaoApex implements strict access controls based on the principle of least privilege. All internal systems require authenticated access, and every action is logged for audit purposes.

Single Sign-On (SSO)

Enterprise SSO integration with Google Workspace, Microsoft Entra ID, and Okta.

Multi-Factor Authentication

TOTP and hardware key support (FIDO2/WebAuthn) for all user accounts.

Compliance & Certifications

TaoApex maintains compliance with international security standards and regulations to protect user data and ensure trustworthy AI operations.

Security audits

Access controls and encryption in transit and at rest. Enterprise customers may request current security documentation.

GDPR & Data Rights

GDPR-aligned practices including data portability, erasure rights, and DPAs for enterprise customers.

Incident Response

Our incident response process follows a clear severity matrix with defined SLAs for communication and resolution.

P1Critical (P1): Acknowledgement within 15 minutes, resolution within 4 hours, customer notification within 1 hour.
P2Major (P2): Acknowledgement within 1 hour, resolution within 8 hours, customer notification within 4 hours.
P3Minor (P3): Acknowledgement within 4 hours, resolution within 48 hours, notification in weekly status report.

Frequently Asked Questions

How does TaoApex protect my data?

TaoApex uses encryption controls described in the privacy policy for data at rest and TLS 1.3 for data in transit. We implement access controls and security reviews. Current audit reports, when available, are provided to enterprise customers on request rather than listed as public certificates.

Is TaoApex GDPR-aligned?

We align our processing with GDPR. We provide data portability, right to erasure, and Data Processing Agreements (DPAs) for enterprise customers. You retain ownership of your data. See the published privacy policy for the current legal basis and processors.

Does TaoApex use my data to train AI models?

No. TaoApex does not use customer data, prompts, or conversations to train any AI models. Your inputs remain private and are never shared with third parties or used for model training purposes.

What happens if there is a security incident?

Our incident response team follows a severity-based process with defined SLAs. Critical issues receive acknowledgement within 15 minutes. All affected customers are notified promptly with clear remediation steps and timelines.

Can I request a security review or penetration test report?

Enterprise customers can request our security posture documentation, including our latest penetration test summary, by contacting our security team through the contact form or emailing security@taoapex.com.

Compare products, learn the underlying workflows, and choose the next step for your use case.

Questions About Security?

Our security team is available to answer your questions and provide documentation for enterprise evaluations.

Contact Security Team