latest update:
[apexdb]

security·posture and sub-processors

Vehicle data only, no PII collected

Standard procurement and InfoSec questions are covered on this page. Questionnaires for the remainder go to security@apex-db.org, reply within 24h.

Minimal PII, consent-gated tracking

The Apex dataset covers vehicles, not people. Customer personal data is limited to buyer name, billing email, and Stripe customer ID. Site measurement is cookieless by default (Vercel Web Analytics); Google Analytics and Google Ads load only after opt-in consent (Consent Mode v2 — denied until you accept). Full detail on the cookies page.

Short-lived, audited downloads

Snapshot download URLs are issued only after authentication and entitlement checks, audited per customer, expire after 1 hour, and can be regenerated from the portal. API tokens are scoped to one org and stored hashed; rotating a token leaves the others active.

Encrypted serving DB, redundant authoring backups

The live serving database is managed Postgres (Neon) — TLS in transit, AES-256 at rest, 7-day point-in-time recovery. The authoring database runs on a hardened host with its datadir on a redundant two-SSD ZFS mirror and frequent copy-on-write recovery points. The Neon serving clone is an independent off-site copy of the published data, refreshed nightly; every value is also reproducible from its public source.

Procurement & compliance pack

Everything a vendor-risk review asks for, standardised and ready — no bespoke negotiation for the basics. Documents marked request come back within 24h from security@apex-db.org.

artifactwhat it isget it
Security posture & sub-processorsThis page — data handling, sub-processor registry, incident response.this page
Licence & redistribution termsPer-tier grant, permitted/prohibited use, source flow-down, attribution./docs/license
Auditor & regulator disclosure carve-outRight to disclose data + provenance to auditors and supervisors for PCAF / CSRD / EBA Pillar 3 — in every tier./docs/license
DPA (data-processing agreement)No customer personal data is processed to deliver the dataset; a DPA is available for procurement checkboxes.request
CAIQ Lite questionnairePre-filled Consensus Assessments Initiative Questionnaire (Lite) for vendor-risk review.request
DORA baseline (EU financial entities)Processing location + change notice, exit / return-of-data, regulator cooperation, Register-of-Information fields.request
Warranty, liability & indemnity postureRight-to-license + methodology warranty; liability capped at fees; capped IP indemnity on the order form./terms

Sub-processors

source: vendor_registry, reviewed quarterly

Vendors that touch any portion of customer data: billing, delivery, transit, storage. Customer notification in writing 30 days before any new sub-processor handling customer data is added.

sub-processorpurposeregion, certifications
StripeBilling and payment processingUS (SOC 2 Type II, PCI DSS Level 1)
VercelWebsite, REST API, and MCP hosting; edge CDN + TLS; snapshot file delivery (Blob)Global edge (SOC 2 Type II, ISO 27001)
NeonLive serving Postgres — the API backing store (read-only clone)us-east-1; EU residency available on Enterprise (SOC 2 Type II)
ResendTransactional email (download links, API tokens, corrections)US / EU (SOC 2 Type II)
Google WorkspaceBusiness email (data@, security@, corrections@)US / EU (ISO 27001, SOC 2 Type II)
Vercel Web AnalyticsCookieless, first-party traffic & Core Web Vitals (no cross-site ID)US / EU (SOC 2 Type II)
Google Analytics & AdsTraffic analytics + ad-conversion measurement — consent-gated (Consent Mode v2); nothing sent before opt-inUS / EU (ISO 27001, SOC 2 Type II)

Responsible disclosure

Reports with reproduction steps to security@apex-db.org. Acknowledgement within 48h, triage within a week. Reporters credited in the changelog unless they opt out.

Out of scope: load-testing of the public API and vulnerability reports about third-party domains outside Apex's control.

Incident response

Affected customers are notified by email within 48 hours of becoming aware of confirmed impact, regardless of regulatory floor. Post-mortems publish on the changelog with a 30-day delay for active mitigation.

View status page