Security & Trust

Security is the product. So is how we handle yours.

You’re being asked to give an advisor access to sensitive systems. Here is exactly how that access is scoped, used, and retired — forward this page to whoever needs to approve it.

Least-privilege, read-only

Engagements request the minimum access needed and nothing more — scoped, read-only credentials you grant and can revoke in one click. No write access, no standing admin.

Written authorization first

No system is scanned without a signed authorization naming the tenant, the scopes, the time window, and the authorizing officer. Access is always something you explicitly grant.

Encryption & short retention

Findings are encrypted at rest. Engagement data is deleted 30 days after delivery; Roust monitoring data is held to a rolling 90-day window.

You execute changes

Axiomeer produces the findings and the revoke-first list — your team executes the changes. Nothing in your environment is altered on your behalf.

Kill switch in your control

For continuous monitoring, access can be cut instantly and permanently at your discretion, at any time, for any reason.

Insured & accountable

Backed by professional (E&O) and cyber liability coverage. Every engagement runs under a mutual NDA and a written services agreement.

Data handling at a glance

What we touch, and for how long

Access

Read-only, least-privilege, time-boxed to the engagement. Granted and revocable by you.

Storage

Encrypted at rest. No copies of your source data leave the engagement scope.

Retention

Assessment/audit data deleted at 30 days; Roust data on a rolling 90-day limit.

Have a vendor security questionnaire or specific requirements? Send it over — I answer them fast, and I speak the language, because reviewing them is part of the work I do for clients.

Questions about access?

Ask before you commit.

Happy to walk your security or IT team through exactly what an engagement touches — before anything is signed.