Trust · Security

Built to be trusted
with your inbound.

Axion is a multi-tenant platform designed for teams that take data seriously. Here's how we protect it.

Tenant isolation

Every workspace is fully isolated — its own use cases, team, conversations, and knowledge base. Data never crosses tenants, enforced at the query layer.

Role-based access

Admin, Agent, and Viewer roles scope what each user can see and do, with last-admin protection so an organisation can't be locked out.

Audit logging

Every sign-in and administrative action is recorded and filterable by actor, client, and date. Nothing happens off the record.

Encryption

Traffic is encrypted in transit. Channel credentials — access tokens and app secrets — are stored encrypted, never in plaintext.

Token governance

Per-client AI-token allowances and live usage meters keep automated spend bounded and visible.

Human-in-the-loop

The agent qualifies and routes; a person makes the call. Escalation to a human is built into every flow.

WhatsApp-policy aligned

Task-specific, knowledge-grounded agents that stay on the qualification job — compliant with the WhatsApp Business Platform by design.

Least-privilege secrets

Secrets live in environment configuration, scoped to the services that need them, and are kept out of source control.

Compliance

Where we are

We build to recognised security practices and are progressing toward formal attestation. If your procurement needs a security questionnaire, sub-processor list, or our Data Processing Agreement, we're glad to provide them.

  • SOC 2 — in progress
  • DPA & sub-processor list — available on request
  • Security questionnaire — happy to complete

Responsible disclosure

Found a vulnerability? We want to hear from you. Email us with details and steps to reproduce, and we'll acknowledge quickly and work with you on a fix. Please don't access data that isn't yours or disrupt the service while testing.

security@axion.ai