Trust & Compliance
Security & Compliance
Axiom Guard is built for regulated enterprise environments. This page covers our HIPAA, GDPR, FISMA, and SOC 2 readiness posture, along with data-retention, encryption, and access-control details your compliance and legal teams will need.
HIPAA Compliance
Axiom Guard is designed as a HIPAA-compatible platform. We do not store Protected Health Information (PHI). The system processes video frames in memory; raw video is discarded after inference and never written to disk or object storage.
Detection-event records (timestamp, location, classification, confidence score, and an anonymized thumbnail) do not constitute PHI under the HIPAA Privacy Rule. If your deployment context requires a Business Associate Agreement (BAA), we make one available on request — contact us to initiate the process.
Audit logs covering all operator actions (login, configuration change, event acknowledgment) are retained for 13 months and are exportable on request. A right-to-erasure path for any individually identified data point is available through the Data Processing Agreement (DPA); contact your account representative or open a request via the DPA portal.
GDPR — Data Processor & Controller Roles
Under the GDPR, your organization acts as the Data Controller and Axiom Guard acts as a Data Processor. We process personal data only on your documented instructions and for no other purpose. A Data Processing Agreement (DPA) is available and can be executed on request.
Lawful bases we rely on depend on your use case: Legitimate Interest (Article 6(1)(f)) for security monitoring in enterprise facilities, and Contract Performance (Article 6(1)(b)) where monitoring is a contractual term between you and the individuals recorded.
Data-subject rights supported: right of access (export on request), right to erasure (tenant-controlled deletion), and right to portability (JSON export via API). EU data residency is available — our European deployment option keeps all processing and storage within EU-region data centers. A cookie notice covering our web properties is published in our Privacy Policy.
FISMA & Federal Deployment
Axiom Guard aligns its security controls to the NIST SP 800-53 Rev 5 control families: Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), System and Communications Protection (SC), and System and Information Integrity (SI).
We are actively pursuing a FedRAMP-Ready designation and can support US Federal agencies on a path to Authority to Operate (ATO). An ATO package — including the System Security Plan (SSP), Policies and Procedures, and control-implementation evidence — is available under NDA for agency review teams.
US Federal deployments are served from FedRAMP-eligible regions. Contact our Federal sales team to discuss deployment architecture, existing ATO artifacts, and timeline.
SOC 2 Readiness
Axiom Guard is in active SOC 2 Type II preparation. The Trust Service Criteria currently in scope are: Security (CC1–CC9), Availability (A1), and Confidentiality (C1–C2).
We have completed internal readiness assessments against all in-scope criteria, implemented continuous control monitoring, and engaged an independent AICPA-accredited audit firm. The audit observation period has commenced.
The SOC 2 Type II report will be available to customers and prospects under NDA on request once issued. In the interim, we provide a Security Questionnaire response and evidence pack on a case-by-case basis for procurement due-diligence.
Data Retention & Encryption
Raw video is never stored by Axiom Guard. Frames are analyzed in-memory and discarded immediately after inference — no video stream reaches our storage layer.
Detection events (anonymized metadata: timestamp, location, classification, confidence, thumbnail) are retained per your tenant policy. The default retention window is 90 days; it is configurable up to 7 years to meet long-term compliance mandates. Operator audit logs are retained for 13 months.
All data at rest is encrypted with AES-256. All data in transit is protected by TLS 1.2 or higher — TLS 1.0/1.1 are disabled at the load-balancer level. Tenant-controlled erasure is available: administrators can delete individual events, purge a date range, or request full-tenant erasure via the DPA process.
Access Controls & Security Operations
Access to Axiom Guard is governed by a role-based access-control (RBAC) model. Admin roles require multi-factor authentication (MFA) — this is enforced at the identity-provider level, not merely recommended. API tokens are scoped to the minimum required privilege (least-privilege scoping) and can be revoked per-token without invalidating other credentials.
Our security operations include continuous SOC monitoring, automated anomaly detection on internal system access, and a defined incident-response playbook. We conduct annual penetration tests performed by a third-party firm and provide executive summaries under NDA on request.
We operate a public vulnerability-disclosure program. Security researchers may report issues through our responsible-disclosure policy; we target a 72-hour acknowledgment and a 90-day remediation window for valid findings. Contact details are published on our security disclosure page.
Ready to review our compliance documentation?
Our team can walk you through a full security review, provide evidence packs for procurement, and execute a DPA for your deployment.