Clear boundaries

Identity, entitlement, and CRM data have distinct jobs.

GDK Apex uses the GDK Digital platform for login and product access while CRM-specific tenant data stays in the application's PostgreSQL data tier.

Architecture answer

How is access separated?

GDK Digital authenticates the user and issues a signed session token. The GDK Apex backend verifies that signature and checks product entitlement through the platform's HTTPS API. CRM records remain in a separate PostgreSQL database and are queried through tenant-scoped application controls.

Shared platform identity

Users sign in through GDK Digital. The Apex application does not need a direct connection to the platform identity database.

Signed-session trust

The backend verifies the platform-issued JWT signature and uses its verified identity fields for the application session.

HTTPS entitlement checks

Product access is checked through the platform entitlement API instead of sharing database credentials across systems.

Separate CRM data tier

Contacts, deals, jobs, invoices, and other CRM records live in the GDK Apex PostgreSQL database.

Tenant-scoped access

Tenant-owned application data is designed to be filtered by the active tenant context, with role and module controls layered on top.

Operational safeguards

Audit, monitoring, encryption, validation, and deployment checks support the application's security and reliability controls.

What this page does not claim

Security information should be specific and supportable.

This page describes verified architecture and product controls. It does not claim a certification, regulatory status, breach history, uptime guarantee, or independent audit that has not been documented by GDK Digital.