You’re being asked to give an advisor access to sensitive systems. Here is exactly how that access is scoped, used, and retired — forward this page to whoever needs to approve it.
Engagements request the minimum access needed and nothing more — scoped, read-only credentials you grant and can revoke in one click. No write access, no standing admin.
No system is scanned without a signed authorization naming the tenant, the scopes, the time window, and the authorizing officer. Access is always something you explicitly grant.
Findings are encrypted at rest. Engagement data is deleted 30 days after delivery; Roust monitoring data is held to a rolling 90-day window.
Axiomeer produces the findings and the revoke-first list — your team executes the changes. Nothing in your environment is altered on your behalf.
For continuous monitoring, access can be cut instantly and permanently at your discretion, at any time, for any reason.
Backed by professional (E&O) and cyber liability coverage. Every engagement runs under a mutual NDA and a written services agreement.
Read-only, least-privilege, time-boxed to the engagement. Granted and revocable by you.
Encrypted at rest. No copies of your source data leave the engagement scope.
Assessment/audit data deleted at 30 days; Roust data on a rolling 90-day limit.
Have a vendor security questionnaire or specific requirements? Send it over — I answer them fast, and I speak the language, because reviewing them is part of the work I do for clients.
Happy to walk your security or IT team through exactly what an engagement touches — before anything is signed.