Security at APEX Regulation Guide

Enterprise-grade security protecting your regulatory research data. We take security seriously so you can focus on compliance.

CSA STAR Level 1
CSA STAR Level 1Verified

Cloud Security Alliance STAR Registry

APEX Regulation Guide is listed on the CSA STAR Registry with a completed CAIQ v4.1.0 self-assessment, documenting our security controls aligned with the Cloud Controls Matrix (CCM).

TLS 1.3 Encryption
Data in transit
Cloud Infrastructure
Secure hosting
No Data Selling
Your data is yours
UAE PDPL Compliant
Data protection

Data Encryption

  • TLS 1.3 encryption for all data in transit
  • Secure HTTPS connections enforced
  • Encrypted database connections
  • Secure API authentication tokens
  • Regular security audits

Infrastructure

  • Hosted on Vercel Edge Network (global CDN)
  • Secure cloud database infrastructure
  • Automatic backups and disaster recovery
  • 99.9% uptime target
  • DDoS protection enabled

Access Control

  • Secure authentication via Clerk
  • Two-factor authentication (2FA) support
  • Session management and timeout
  • SSO integration (Enterprise plan)
  • Role-based access for teams

Compliance

  • UAE PDPL compliant (data protection)
  • PCI-DSS compliant payments via Stripe
  • Privacy by design principles
  • Data export and deletion on request
  • Transparent privacy policy

AI Processing Security

When you use our AI-powered search and analysis features:

Query Processing
Search queries are processed securely via OpenAI's API with enterprise-grade security.
No Training
Your queries are not used to train AI models. OpenAI does not retain API data for training.
Minimal Data
We only send the minimum data needed for search processing. No personal data included.

Security Vulnerability Reporting

If you discover a security vulnerability in APEX Regulation Guide, please report it responsibly. We appreciate your help in keeping our platform secure.

security@apex-reg.com

Platform Security Updates

We continuously enhance our UAE building regulations platform with new security features, compliance tools, and infrastructure improvements.

Security Update

APX-2026-021701

Released
February 17, 2026

PDF Serving Migration & Cloudflare R2 Integration

Major infrastructure update migrating official regulation PDFs (Dubai Building Code, DEWA, Civil Defense, Abu Dhabi UPC) to Cloudflare R2 edge storage. This update improves document loading speeds and ensures reliable access to source materials.

Cloudflare R2: Global edge distribution for UAE building regulation PDFs with page-level deep links
Ingest Security: Removed public ingest routes - database writes only via authenticated local scripts
Rate Limiting: API rate limit headers exposed for client-side quota management
CORS Policy: Configured secure CORS with explicit method and header allowlists
Cloudflare R2PDF SecurityAPI HardeningRate LimitingInfrastructure
Security Update

APX-2026-010502

Released
January 5, 2026

Qdrant Vector Database & Semantic Search Launch

Introduced semantic search powered by Qdrant vector database and OpenAI embeddings. 3,000+ regulation chunks from Dubai Building Code, Civil Defense Fire Code, Al Sa'fat, Abu Dhabi UPC indexed with article-level metadata.

Qdrant Cloud: Managed vector database with encrypted connections and payload indexing
OpenAI Embeddings: text-embedding-3-small for semantic similarity search on regulations
Metadata Filtering: Secure filtering by emirate, authority, code name, and version
Source Citations: Every search result links to official PDF page for verification
QdrantOpenAIVector SearchPDF ParsingRegTech

Related Topics

UAE Building RegulationsDubai Building CodeDEWA ComplianceCivil Defense RequirementsAl Sa'fat CertificationConstruction Compliance UAEBuilding Permit DubaiMEP RegulationsFire Safety Code UAEAbu Dhabi Building Code