Last Updated: April 23, 2026
All data encrypted using AES-256 at rest in TiDB Cloud and Amazon S3.
All connections secured with TLS 1.2+ — no unencrypted data transmission.
Role-based access control. Admin and client roles with least-privilege enforcement.
JWT-based session tokens with secure HttpOnly cookies. OAuth 2.0 for admin access.
All admin actions and data access events are logged with timestamps and user identity.
Call recordings retained 12 months. Personal data deleted within 30 days of account termination.
The ALI platform is hosted on enterprise-grade cloud infrastructure. Our database is powered by TiDB Cloud (PingCAP), which provides automatic failover, point-in-time recovery, and geo-redundant backups. File storage uses Amazon S3 with server-side encryption enabled on all buckets. All services run behind a reverse proxy with DDoS protection and rate limiting.
| Framework | Status | Notes |
|---|---|---|
| TCPA Compliance | ✓ Active | RND checks, DNC enforcement, consent tracking |
| CAN-SPAM Compliance | ✓ Active | Physical address, unsubscribe mechanism, honest headers |
| CCPA Compliance | ✓ Active | Do Not Sell page, privacy request form, data deletion |
| SOC 2 Type II | ⏳ In Progress | Audit preparation underway — expected 2026 |
| GDPR | ⏳ Partial | DPA available; SCCs available on request |
If you discover a security vulnerability in the ALI platform, please report it responsibly to [email protected] with the subject line "Security Vulnerability Report." We will acknowledge receipt within 48 hours and work to resolve confirmed issues within 30 days. We do not currently offer a bug bounty program but appreciate responsible disclosure.
Apex Lead Intelligence LLC
202 Walton Way Suite 192 Unit #715, Cedar Park, Texas 78613
Security contact: [email protected]