Updated 2026-08-18.

Security

Hosting and infrastructure

Apex BDC runs on US-based cloud infrastructure operated on our behalf by vetted providers that maintain SOC 2 Type II and ISO 27001 attestations. Data-processing regions are limited to the United States for all customer records.

Encryption

Data is encrypted in transit using TLS 1.2 or higher. Data is encrypted at rest using AES-256 or the industry-equivalent algorithm published by our storage providers.

Tenant isolation

Each dealership rooftop is a logically isolated tenant. Row-level security is enforced at the database layer so no user can query or read data from another tenant.

Access control

All administrative access is behind single sign-on with mandatory hardware-key or authenticator-app second factor. Production access is limited to named engineers, logged, and reviewed quarterly.

Data handling

Customer data is used only to operate the Apex BDC service for that dealership. It is never sold, shared with unrelated third parties, or used to train models shared across dealerships.

Telephony and messaging compliance

Outbound calling includes SHAKEN/STIR A-level attestation and CNAM display. Outbound messaging is A2P 10DLC registered or Toll-Free verified per rooftop. Quiet-hours rules and opt-out language are enforced automatically.

Subprocessors

A current list of Apex BDC's subprocessors is provided to customers under NDA as part of Data Processing Addendum execution. Request the list from legal@apexbdc.ai.

Incident response

Security incidents are triaged within one business hour of detection. Affected customers are notified in accordance with contractual and statutory obligations.

Reporting a vulnerability

Email security@apexbdc.ai. We acknowledge reports within one business day.

AutoCity LLC dba Apex BDC, 585 Chestnut Street, Union, NJ 07083.