Data protection
Encryption in transit and at rest for hosted workspaces. Customer content is logically isolated by organization.
Security
Axovern is built for teams that must show their work. This page summarizes how we protect platform and customer data, without publishing details that would help an attacker.
Encryption in transit and at rest for hosted workspaces. Customer content is logically isolated by organization.
Role based permissions, workspace isolation, optional SSO, MFA for privileged accounts, and scoped auditor access.
Material workspace actions are logged so administrators and auditors can review who changed what, and when.
We practice what we sell: continuous controls, clear ownership, and evidence you can point to when buyers ask. Detailed architecture, penetration test summaries, and questionnaire responses are shared under NDA during a formal security review.
Axovern operates a security and compliance program aligned with the frameworks our customers use: including SOC 2, ISO 27001, HIPAA, GDPR, and NIST CSF. We treat our own platform with the same rigor we help customers demonstrate to their buyers.
This public page is a summary. It is not a substitute for a completed questionnaire, signed DPA, or customer specific Trust Center content.
Hosted workspace data is encrypted in transit and at rest. Backups and production environments are separated by access controls. We limit production access to authorized personnel with a business need.
Customers choose what data enters a workspace: including evidence, personnel records, vendor information, and integration metadata. You control retention and export through your workspace and agreement with us.
Hosted workspaces are provisioned in a data region chosen when the workspace is created: United States (Oregon) or Canada (Montreal). The region applies to primary customer workspace data stored on our platform, including controls, evidence, audit logs, integration tokens, and related program artifacts.
Customers use the same product URLs (app.axovern.com, api.axovern.com) regardless of region. Published Trust Centers may display the workspace data location for your buyers.
Important: Some optional features use sub processors that may process data outside your selected region (for example AI inference, transactional email, or SSO). See our Sub processors page and your DPA for details. Customer configured integrations (GitHub, Okta, cloud providers, and similar) are governed by your agreements with those vendors.
We do not currently offer a dedicated European Union or United Kingdom data region. Cross border transfer safeguards for EEA and UK customers are described in our Privacy Policy.
Hosted workspaces support role based access control and organization level isolation. Optional single sign on (Google or Microsoft, when provisioned for your workspace) and multi factor authentication for privileged accounts help enforce least privilege.
External auditor access uses time limited, scoped invitations, not standing admin accounts. The dedicated auditor portal exposes only what is required for the engagement.
The hosted platform runs on enterprise cloud infrastructure operated by our sub processors (see our Sub processors page). Customer workspace data is stored in the United States or Canada depending on the data region selected at provisioning.
We design for availability and maintain backups appropriate to a business critical SaaS service. We do not publish network diagrams, internal service names, or detailed infrastructure topology on this page.
Production changes follow reviewed deployment processes. We monitor the hosted environment for availability and security relevant events and review access to production systems on a recurring basis.
Third party providers we rely on are listed on our Sub processors page. We assess subprocessors before onboarding and when material changes occur.
We maintain incident response procedures designed to contain, investigate, and remediate security events affecting the service. Where we are the processor, we notify affected customers without undue delay when a personal data breach is confirmed, consistent with our agreements and applicable law.
We welcome responsible disclosure of potential vulnerabilities. Report issues to [email protected]. Please include enough detail for us to reproduce the issue; do not access data belonging to other customers.
The Axovern desktop app can store workspace data locally on your device. In hosted mode, the app syncs through the same authenticated API model as the web application. Local deployments remain your responsibility for device security, patching, and backup.
Prospective and current customers often send vendor security questionnaires. We respond through our security team and can provide additional documentation under NDA where appropriate.
Axovern customers can also publish a read only Trust Center from their own workspace. The same product capability we recommend for deflecting inbound security reviews.
Security questions and vulnerability reports: [email protected]
Privacy and data protection: [email protected]
Related: Privacy · Sub processors · Terms
FAQ
Encryption in transit and at rest, role based access, optional SSO and MFA, audit logging, and organization level isolation on cloud infrastructure operated by our sub processors. United States and Canada workspace regions are available at provisioning.
Email [email protected] with responsible disclosure details. Do not access data belonging to other customers. We investigate and respond through our incident procedures.
We operate a security program aligned with the frameworks our customers use. We do not publish certificates, penetration test results, or architecture diagrams on this site. Prospective and current customers can request review materials under NDA, email [email protected] with your questionnaire or review timeline.
When Axovern processes protected health information in your hosted workspace as your vendor, healthcare customers can request a Business Associate Agreement alongside our data processing terms during enterprise onboarding. Contact [email protected] during procurement, this is separate from tracking your own vendors' BAAs inside the product.
Email us with your questionnaire or request a call. For product details on customer facing trust pages, see Trust Center.