// Security & trust
We ask for the keys to your systems.
Here's how we treat them.
Hiring an IT partner is an act of trust. This page is the unglamorous detail of how we earn it — the same standards we are paid to build for clients, applied to ourselves.
// Operating practices
Secure development lifecycle
Code review on every change, static analysis and dependency scanning in CI, and security checkpoints built into each delivery milestone — not bolted on at the end.
Least-privilege access
Client systems are accessed through SSO with MFA, scoped to the minimum required role, time-boxed where possible, and revoked automatically when an engagement ends.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest, and secrets in managed vaults — never in repositories, chat, or spreadsheets. We hold no client credentials outside approved vaults.
Audit trails by default
Administrative actions on managed systems are logged immutably. Clients can review who touched what, when — and we walk through it together in quarterly reviews.
Tested recovery
Backups are worthless until restored. Managed systems get scheduled restore drills with documented RPO/RTO — and the drill results go in your quarterly report.
Vendor & supply-chain discipline
Dependencies are pinned and scanned, base images are minimal and rebuilt on schedule, and third-party services we introduce go through the same risk review we run for clients.
// Compliance posture
SOC 2 Type II
Our own report — renewed annually, available under NDA
ISO 27001
Aligned controls; client certification programs delivered
HIPAA
BAA-covered delivery for healthcare clients
PCI DSS
Scoped architectures & audit support for payment systems
GDPR / CCPA
DPAs signed; privacy-by-design in scoped projects
Security questionnaires, vendor-risk reviews, and audit evidence requests: security@axioratrust.com
// Responsible disclosure
Found a vulnerability in our website or systems? We want to hear about it — and we commit to acknowledging reports within 2 business days, not prosecuting good-faith research, and crediting researchers who want credit. Report to security@axioratrust.com with steps to reproduce. Please avoid accessing client data; a proof of concept against our own assets is always enough.
Need this level of rigor on your systems?
Our security practice builds exactly these programs for clients — assessments, hardening, and compliance that passes audit the first time.