Your code, your data, your accounts. Day one.
What a procurement officer or technical buyer should know about how Apptology handles security, data, and access — in plain language.
Our stance
We sign your NDA before the first call — or bring ours if you don't have one. Everything you share is confidential by default, not by negotiation.
You own your code, your data, your domains, and your accounts from day one. Repos, cloud, and DNS live in your name; if we part ways, you lose nothing but our company.
We don't run side-projects on client infrastructure, and we don't accept referral payments from cloud or tooling vendors. Recommendations you get from us are unbought.
Certifications and process
- CMMI Level 3 appraised process — written estimation, blocking reviews, change control, and published retros.
- ISO-aligned security posture (alignment, stated honestly — we'll tell you precisely which controls, on request).
- GDPR-aware and UAE PDPL-aligned data handling as the default on every build.
Data handling
- Client data lives in your accounts, in UAE/GCC regions by default.
- Nothing moves outside the GCC without a written ask and your written yes — including analytics and error-tracking services.
- Project materials are deleted from our systems within 60 days of project close, unless you ask us to retain them.
Access control
- Named individuals only — you'll know exactly who on our side can touch your systems.
- Least-privilege by default; production access is the exception, logged when it happens.
- Offboarding within 24 hours of a team change, with access revocation you can verify.
AI-specific commitments
- We never train third-party models on your data — contractually and architecturally.
- We use enterprise/B2B API tiers of model providers where available, with data-retention switched off.
- Agent autonomy has a line: destructive or financial actions require human confirmation, always.
If something goes wrong
You hear it from us first: notification within 24 hours of confirming an incident affecting your systems or data, a clear account of impact, and a written post-mortem. No euphemisms, no burying it in a status page.
Anything missing?
If your review needs something not listed here — questionnaires, architecture walkthroughs, specific controls — ask. We've probably done it before.
Questions your review still has?
Security questionnaires, architecture walkthroughs, or a call with our security lead — ask, and it's arranged.

