Security
What protects your records in Axia, stated as it is built.
Separation between organizations
- Row-level security in Postgres
- The application connects as a database role that can only see the rows of the current organization. A mistake in code does not become a leak between companies.
- Checked on every build
- An isolation test matrix runs across the endpoints, once with row-level security and once without it, so each layer has to hold on its own.
- Files per organization
- Uploaded evidence is stored under the organization’s own path and served only to its members.
Access
- Two-factor sign-in
- TOTP for every account. An organization can require it, and a test fails while any member lacks it.
- Single sign-on
- OIDC per organization, on the Business plan.
- Roles
- A central role matrix decides who can read or change each module, including a role for the information security manager.
- Sessions and sign-in
- Rate limiting and lockout at sign-in, session length set per organization, sessions revoked on demand.
Data
- Encryption keys per organization
- Secrets and connector credentials are encrypted with a key that belongs to one organization.
- Audit log
- Every change is recorded with who made it and when. The log survives the deletion of the organization, apart from it.
- Export and deletion
- A full export as an archive with a manifest. Deletion keeps the data for 30 days in case of a mistake, then removes it and issues a certificate.
- Backups
- Encrypted backups, with a restore exercise that is itself recorded.
- Where the data is
- The data and its backups are hosted in the EU. Sub-processors are listed publicly, and changes are announced 30 days before they take effect.
What we do not claim
Axia prepares the evidence; certification is granted by an accredited certification body after its own audit. The ISO standards’ text is copyrighted and sold by ISO, so Axia ships their codes and titles, not their wording. Your own licensed copy can be added after you attest the licence.
