Trust Center

Security you can verify

AxisSynapse protects customer data with controls that are enforced continuously and mapped to the frameworks our customers require. Here is how — and how to reach us.

Encryption everywhere

TLS in transit; AES-256-GCM at rest through one canonical envelope. Keys custodied in Azure Key Vault via Managed Identity, rotatable with zero downtime.

Strong authentication

TOTP + phishing-resistant WebAuthn/passkeys, SAML SSO + SCIM lifecycle, and step-up re-auth for high-impact actions.

Least-privilege access

Deny-by-default RBAC, 4-eyes separation of duties, per-tenant IP policy, session revoke, and quarterly access reviews.

Immutable audit

Every privileged action is written to an append-only, hash-chained log with jurisdiction-aware retention floors.

Tenant isolation

Each customer's data lives in its own PostgreSQL schema; capacity-bounded cells with tested live migration.

Continuous monitoring

Build-blocking security gates, dependency scanning, synthetic monitoring, SLOs, and derived security alerts.

Compliance program

Our technical controls are catalogued in machine-readable OSCAL and mapped to SOC 2 (all five Trust Services categories), NIST 800-53 / 800-171, and ISO 27001. A continuous evidence bundle keys every control to the CI gate that tests it, so an audit is a matter of sampling — not scrambling.

SOC 2 (Type II)NIST 800-53r5NIST 800-171ISO 27001GDPR / DPA

Resources

Talk to our security team

For security reviews, questionnaires, or the SOC 2 report under NDA, email security@axissynapse.com. Our disclosure manifest is at /.well-known/security.txt.