Your data is walled off from every other customer.
Apexor is multi-tenant by design. Each organization’s records are isolated at two independent layers — scoped in the application and enforced again in the database — so one customer can never see another’s data.
How isolation works
Two independent walls: the application scopes every request to your organization, and the database enforces the same boundary with row-level security.
Isolation, step by step
You sign in
Each user authenticates and is bound to exactly one organization and role. The session carries that identity on every request.
The app scopes every query
Our data layer automatically injects your organization's ID into every read and write. Application code cannot ask for another company's records.
The database enforces it again
Row-Level Security in the database is a second, independent wall: even a flawed query cannot return another tenant's rows. Isolation is enforced where the data lives, not just in the app.
Your data stays yours
Every table carries an organization ID, so leads, appointments, messages, and files are partitioned per customer. One tenant can never read or write another's data.
More safeguards
Encrypted in transit
All traffic is served over TLS (HTTPS); data is encrypted at rest where our infrastructure provides it.
Least-privilege access
Staff access is role-based and limited to what's needed to run and support the Services.
Secrets isolation
Credentials and provider keys are stored as managed secrets, separated from code and per environment.
Backups & monitoring
We keep routine backups and monitor the platform. You should also export and keep your own backups regularly.
Read how this fits our data commitments in the Data Processing Agreement and Privacy Policy.
