Backups and data security: what's on you, and what's on the platform

Before you hand your company's data to any system, it's worth knowing where your responsibility ends and the provider's begins. We summarize what to ask and what you should be sure of.

Marek Raja

The question "is it safe" comes up with every system a company hands its data to - and it's the right question. The problem is that the answer tends to be either too general ("yes, of course") or so technical that it doesn't actually help anyone decide. It's more useful to break security down into specific, verifiable questions.

Three questions you should know the answer to

Who backs up the data, and how often. For a cloud application, backups should be part of the platform, not something each team has to handle separately with its own export to a file.

Who on the team sees and can change what. A shared password to a single file is not access control - real permissions mean each person on the team sees only what they should, based on their role.

Whether you can see afterward who changed what. When something goes wrong (a bad value, a deleted record), there should be a way to find out who did it and when - without this traceability, an error only ever gets fixed, never understood.

What you should be sure of with any business system

Three basic questions any business system provider should be able to answer clearly - no matter how they're solved technically.

What the platform already handles for you

Role-based access control, not a shared password, is one of the things Apexloop handles directly - permissions are set at the level of the page, the database and individual columns, and inherit automatically into subpages, so you don't have to set them up for every order or client separately. We cover this in detail in the article on access rights.

For specific questions about backups and infrastructure, which vary by deployment type and plan, we recommend booking a short call - you'll get a precise answer for your specific case, not a general statement.

What to ask, whatever system you're considering

Whether you're considering Apexloop or anything else, it's worth asking every provider the same three things: how often and where backups happen, how access for individual team members is controlled, and whether a change history is traceable. An answer of "we don't know" or an evasive answer is itself useful information.

The same kind of questions, but for AI tools - where the data goes, who holds it and whether it's trained on - are in You upload company data into AI. Where does it actually go?.

Frequently asked questions about backups and data security

Do I have to handle backups myself, or does the platform do it?

For a cloud application, backups should be part of the platform. For exact details based on your plan and deployment type, get in touch directly - we're happy to go through it for your specific case.

How do I find out who on the team edited a specific record?

A record's change history shows who changed a value and when, which is the basic requirement not just for fixing an error, but for understanding why it happened.

Is it safer to keep data in Excel on your own computer, or in a cloud application?

A local file with no access control and no backup is more vulnerable to data loss (a disk failure, an accidental deletion) and to anyone who gets hold of the file itself having access to it. A cloud application with role-based access control and centralized backups significantly reduces this risk.

Ask directly about what matters to you in data security.

Apexloop builds a tailored app for you