Encryption everywhere
TLS 1.2+ in transit and AES-256 at rest. Keys are managed and rotated; nothing is written unencrypted.
Axiom is built for teams that keep everything, so security is not a tier you buy later. Encryption, access control, audit, and compliance are part of the platform — and your data stays in your control.
Reports and certificates are available under NDA in the Trust Center. Procurement gets what it needs without a sales gate.
SOC 2 Type II
Independently audited security controls with reports available in our Trust Center.
ISO 27001
Certified information security management, audited to the international standard.
GDPR
Built to support GDPR requirements with privacy-first data handling.
HIPAA BAA
Sign a Business Associate Agreement for HIPAA-compliant healthcare workloads.
Regional residency
Keep your data in your chosen region with multi-region edge architecture.
TLS 1.2+ in transit and AES-256 at rest. Keys are managed and rotated; nothing is written unencrypted.
SAML and OIDC single sign-on, SCIM provisioning, and role-based access control scoped to datasets and actions.
Every access and configuration change is recorded to an immutable audit trail you can query in APL like any other dataset.
Workspaces are logically isolated on a fully managed, multi-tenant event store with strict per-tenant access boundaries.
Choose where your data lives. Query-time redaction keeps sensitive fields masked on read without stripping them from storage.
Object-storage durability and ephemeral compute, with status and incident history published openly.
Any Axiom web service that handles reasonably sensitive user data is intended to be in scope. This includes virtually all the content in all of axiom.co and its subdomains.
The program has an important exclusion to keep in mind:
Third-party websites. Some Axiom-branded services hosted in less common domains may be operated by our vendors or partners. We can’t authorize you to test these systems on behalf of their owners and will not reward such reports. If in doubt, talk to us first!
There are no rewards for security issues that are trivial or broadly applicable to every service. The following types of reports are considered out of scope:
Missing password complexity requirements
Self-XSS
User / organization existence or enumeration vulnerabilities
Insecure cookie settings for non-sensitive cookies
Bugs requiring exceedingly unlikely user interaction
Reports from automated tools or scans (without accompanying demonstration of exploitability)
To submit a report, please email security@axiom.co
Any design or implementation issue that substantially affects the confidentiality or integrity of user data is likely to be in scope for the program. Common examples include:
authentication or authorization flaws
cross-site scripting
cross-site request forgery
server-side code execution bugs
Note that the scope of the program is limited to technical vulnerabilities in Axiom-owned web applications. This program excludes:
social engineering or phishing attacks against our employees
issues related to use of out-of-date browsers and plugins
spam of any kind
Out of concern for the availability of our services to all users, please do not attempt to carry out DoS attacks, leverage black hat SEO techniques or do other similarly questionable things. We also discourage the use of any vulnerability testing tools that automatically generate very significant volumes of traffic.
All rewards are at our discretion. We attempt to align any award appropriately with the severity of the security risk.
In transit
Encrypted end to end. Data is encrypted from your services to Axiom over TLS, with modern cipher suites enforced at the edge.
At rest
Encrypted and durable. Events are stored encrypted on durable object storage. Retention is yours to set, not a default that drops data.
In your control
Masked on read. Query-time redaction keeps PII out of results without deleting it, so access is governed without losing the record.
Talk to our team about security review, or start on the Trust Center.