Security you can verify
AxisSynapse protects customer data with controls that are enforced continuously and mapped to the frameworks our customers require. Here is how — and how to reach us.
TLS in transit; AES-256-GCM at rest through one canonical envelope. Keys custodied in Azure Key Vault via Managed Identity, rotatable with zero downtime.
TOTP + phishing-resistant WebAuthn/passkeys, SAML SSO + SCIM lifecycle, and step-up re-auth for high-impact actions.
Deny-by-default RBAC, 4-eyes separation of duties, per-tenant IP policy, session revoke, and quarterly access reviews.
Every privileged action is written to an append-only, hash-chained log with jurisdiction-aware retention floors.
Each customer's data lives in its own PostgreSQL schema; capacity-bounded cells with tested live migration.
Build-blocking security gates, dependency scanning, synthetic monitoring, SLOs, and derived security alerts.
Compliance program
Our technical controls are catalogued in machine-readable OSCAL and mapped to SOC 2 (all five Trust Services categories), NIST 800-53 / 800-171, and ISO 27001. A continuous evidence bundle keys every control to the CI gate that tests it, so an audit is a matter of sampling — not scrambling.
Resources
Live uptime + incident history.
Criteria, period, request under NDA.
Who processes your data.
Coordinated disclosure + safe harbor.
For security reviews, questionnaires, or the SOC 2 report under NDA, email security@axissynapse.com. Our disclosure manifest is at /.well-known/security.txt.