AXIORA TRUST

// Security & trust

We ask for the keys to your systems. Here's how we treat them.

Hiring an IT partner is an act of trust. This page is the unglamorous detail of how we earn it — the same standards we are paid to build for clients, applied to ourselves.

// Operating practices

Secure development lifecycle

Code review on every change, static analysis and dependency scanning in CI, and security checkpoints built into each delivery milestone — not bolted on at the end.

Least-privilege access

Client systems are accessed through SSO with MFA, scoped to the minimum required role, time-boxed where possible, and revoked automatically when an engagement ends.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest, and secrets in managed vaults — never in repositories, chat, or spreadsheets. We hold no client credentials outside approved vaults.

Audit trails by default

Administrative actions on managed systems are logged immutably. Clients can review who touched what, when — and we walk through it together in quarterly reviews.

Tested recovery

Backups are worthless until restored. Managed systems get scheduled restore drills with documented RPO/RTO — and the drill results go in your quarterly report.

Vendor & supply-chain discipline

Dependencies are pinned and scanned, base images are minimal and rebuilt on schedule, and third-party services we introduce go through the same risk review we run for clients.

// Compliance posture

SOC 2 Type II

Our own report — renewed annually, available under NDA

ISO 27001

Aligned controls; client certification programs delivered

HIPAA

BAA-covered delivery for healthcare clients

PCI DSS

Scoped architectures & audit support for payment systems

GDPR / CCPA

DPAs signed; privacy-by-design in scoped projects

Security questionnaires, vendor-risk reviews, and audit evidence requests: security@axioratrust.com

// Responsible disclosure

Found a vulnerability in our website or systems? We want to hear about it — and we commit to acknowledging reports within 2 business days, not prosecuting good-faith research, and crediting researchers who want credit. Report to security@axioratrust.com with steps to reproduce. Please avoid accessing client data; a proof of concept against our own assets is always enough.

Need this level of rigor on your systems?

Our security practice builds exactly these programs for clients — assessments, hardening, and compliance that passes audit the first time.