Security & Trust

Security you can verify, not just trust

AxioRank is built on a simple idea: a security product should be able to prove its own claims. Here is how we protect your data, and the evidence we hand you to check it yourself.

Provable audit trail

Every governed decision lands in a tamper-evident, Merkle-sealed log. You can verify any receipt offline with an open-source library, without trusting us or even reaching our servers.

Compliance evidence on demand

Export an offline-verifiable evidence bundle for SOC 2 and ISO audits straight from the dashboard: sealed audit checkpoints, configuration history, and retention proofs in one archive.

Workspace security controls

SAML single sign-on, enforced MFA, four-level role-based access, scoped API keys with rotation and expiry, configurable data retention, and IP masking are all built in.

Privacy and data rights

Self-service data export and deletion, jurisdiction-aware response deadlines, and a documented retention schedule. We support GDPR, CCPA/CPRA, and the broader US state privacy laws.

Data processing terms

Our Data Processing Agreement covers GDPR Article 28, UK GDPR, and Swiss FADP obligations, with Standard Contractual Clauses for international transfers.

Availability and support

Enterprise subscriptions carry a 99.9% monthly uptime commitment with service credits, and every plan has documented support response targets. The status page shows live component health and 90 days of uptime history.

Infrastructure

AxioRank runs on audited cloud providers (Vercel and Supabase, both SOC 2 Type II attested), with encryption in transit and at rest, isolated per-workspace data, and deny-by-default row-level security.

Data residency

Customer data is stored in the United States today, and we say so plainly rather than implying otherwise. The optional ML assessment lane can be pinned to EU compute for workspaces set to the EU region. EU teams keep further control through gateway-side redaction, configurable retention, SIEM streaming into infrastructure you run in your own region, and self-service export and erasure.

Certifications and testing

Our SOC 2 Type II engagement is in progress; the report will be available under NDA. Independent penetration testing is performed against the gateway and dashboard, with summaries available to customers on request.

Reporting a vulnerability

If you believe you have found a security issue in AxioRank, email hi@axiorank.com with the details. We acknowledge reports within two business days and keep you informed while we investigate. Please give us a reasonable window to remediate before public disclosure.