ÿÿSecurity and compliance, by default — Axiom

Security

Security and compliance, by default.

Axiom is built for teams that keep everything, so security is not a tier you buy later. Encryption, access control, audit, and compliance are part of the platform — and your data stays in your control.

Attestations

Audited, attested, and verifiable.

Reports and certificates are available under NDA in the Trust Center. Procurement gets what it needs without a sales gate.

SOC 2 Type II

Independently audited security controls with reports available in our Trust Center.

GDPR

Built to support GDPR requirements with privacy-first data handling.

HIPAA BAA

Sign a Business Associate Agreement for HIPAA-compliant healthcare workloads.

Regional residency

Keep your data in your chosen region with multi-region edge architecture.

How it is protected

Controls across data, access, and infrastructure.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest. Keys are managed and rotated; nothing is written unencrypted.

SSO & RBAC

SAML and OIDC single sign-on, SCIM provisioning, and role-based access control scoped to datasets and actions.

Audit logging

Every access and configuration change is recorded to an immutable audit trail you can query in APL like any other dataset.

Tenant isolation

Workspaces are logically isolated on a fully managed, multi-tenant event store with strict per-tenant access boundaries.

Data residency

Choose where your data lives. Query-time redaction keeps sensitive fields masked on read without stripping them from storage.

Reliability

Object-storage durability and ephemeral compute, with status and incident history published openly.

Your data stays yours

Three guarantees about your data.

In transit

Encrypted end to end. Data is encrypted from your services to Axiom over TLS, with modern cipher suites enforced at the edge.

At rest

Encrypted and durable. Events are stored encrypted on durable object storage. Retention is yours to set, not a default that drops data.

In your control

Masked on read. Query-time redaction keeps PII out of results without deleting it, so access is governed without losing the record.

Keep everything. Secure by default.

Talk to our team about security review, or start on the Trust Center.

ÿÿÿÿ