Security & Trust

Trust Centre

Your security and privacy are foundational to everything we build. Learn about our commitment to protecting your data and maintaining the highest standards of compliance.

SOC 2

Type II · In progress

ISO 27001

In progress

ISO 42001

In progress
Certifications & Roadmap

Security & Compliance

We maintain rigorous security standards and are actively working toward the industry's leading certifications. We align our controls to their requirements as we prepare for formal audits.

SOC 2 Type II In progress

We are preparing for a SOC 2 Type II audit - implementing and documenting controls across security, availability, processing integrity, confidentiality and privacy ahead of a formal assessment.

  • Formal Type II audit planned with an accredited auditor
  • Controls being implemented, tested and evidenced
  • Reports will be available to customers under NDA once certified

ISO 27001 In progress

We are implementing an Information Security Management System aligned to the internationally recognised ISO 27001 standard and working toward certification.

  • Systematic approach to managing sensitive information
  • Certification audit planned; surveillance audits to follow
  • Continuous improvement of security practices

ISO 42001 In progress

We are establishing an AI Management System aligned to ISO 42001 - the international standard for responsible AI governance - and working toward certification.

  • Governance for AI risk, oversight and accountability
  • Aligns our own practices with the controls we provide customers
  • Pursued alongside our ISO 27001 programme

GDPR Compliance

Full compliance with the EU General Data Protection Regulation, ensuring the highest standards of data privacy and protection.

  • Data Processing Agreements available
  • Right to access, rectify, and delete data
  • Data portability and breach notification

Industry Standards

We support compliance with HIPAA, CCPA, and other regulatory frameworks specific to your industry requirements.

  • HIPAA-compliant configurations available
  • CCPA privacy rights support
  • Industry-specific compliance guidance
Infrastructure

Infrastructure Security

Enterprise-grade infrastructure with multiple layers of security to protect your data.

Infrastructure

Cloud infrastructure hosted on AWS with geographic redundancy and 99.9% uptime SLA.

Encryption

AES-256 encryption at rest and TLS 1.3 in transit. All data encrypted with unique keys.

Access Control

Role-based access control, multi-factor authentication, and principle of least privilege.

Network Security

Web application firewall, DDoS protection, and intrusion detection systems.

Data Backup

Automated daily backups with point-in-time recovery and cross-region replication.

Monitoring

24/7 security monitoring with automated alerting and incident response procedures.

Privacy

Data Privacy

Your data is yours. We maintain strict data handling policies and provide full transparency.

Data Ownership

You retain full ownership of your data. We act solely as a data processor and never use your data for any purpose other than providing our services.

  • Complete data ownership and control
  • Data export available at any time
  • Secure data deletion upon request

Data Residency

Choose where your data is stored with regional data centers. All data remains within your selected geographic region.

  • Multiple geographic regions available
  • Data sovereignty compliance
  • On-premises deployment options

Data Processing

We process data only as necessary to provide our services and in accordance with your instructions and applicable regulations.

  • Minimal data collection principles
  • Purpose limitation and transparency
  • No third-party data sharing

Sub-Processors

We maintain a limited list of vetted sub-processors and notify customers of any changes with advance notice.

  • Amazon Web Services (AWS)Cloud infrastructure provider
  • SupabaseDatabase and authentication services
  • CloudflareCDN and DDoS protection
  • SentryError monitoring and performance tracking
  • SendGridEmail delivery services
  • Comprehensive sub-processor vetting and security reviews
  • 30-day advance notice for any changes to sub-processors
  • All sub-processors bound by data processing agreements
Operations

Security Practices

Continuous security improvements through testing, training, and industry best practices.

Vulnerability Management

Regular security assessments, penetration testing, and vulnerability scanning. All critical vulnerabilities addressed within 24 hours.

Incident Response

24/7 security operations center with documented incident response procedures. Customer notification within 72 hours of any data breach.

Employee Security

Comprehensive background checks, security training, and NDA requirements. Regular security awareness training for all employees.

Security Development

Secure software development lifecycle with code reviews, static analysis, and security testing integrated into our development process.

Demonstration Website

Website Security & Threat Surface

Axonyx operates a public demonstration website to showcase product capabilities. The demo environment presents a minimal attack surface with no administrative functionality, authentication interfaces, or customer data exposure.

Security Validation

The demo site is scanned continuously. Recent cycles show no critical, high or medium-severity findings, a secure baseline configuration, correct transport security and no common web application vulnerabilities.

No Exploitable Vulnerabilities Identified

  • No SQL injection or command execution paths
  • No cross-site scripting or CSRF vulnerabilities
  • No file inclusion or path traversal risks
  • No credential leakage or authentication bypass
  • No exposed API endpoints or administrative interfaces

Secure Transport Configuration

  • TLS 1.2+ enforced with trusted certificates
  • No mixed content or insecure resource loading
  • No directory listing or information disclosure
  • No sensitive data exposure in responses
  • Secure cookie attributes and session handling

Configuration Hardening

Automated scanning identified several low-risk configuration opportunities related to optional HTTP security headers. These findings represent defense-in-depth enhancements rather than exploitable vulnerabilities and are common in static demonstration environments.

Risk Classification

Remaining hardening recommendations are low-risk and informational. None is an exploitable attack vector, and the site is static, which makes several browser controls largely irrelevant here.

Remediation Approach

Low-risk findings are tracked and fixed on practical impact, where they add real security value.

Threats Addressed

Endpoint Enumeration & Discovery

The site exposes static content and a contact form. No API endpoints, admin interfaces or hidden functionality, so fingerprinting yields little.

Injection-Based Attacks

Testing confirms no SQL injection, command injection or code execution. The static architecture removes server-side processing of user input beyond the contact form, which uses a secure third-party email service.

Client-Side Abuse & Data Leakage

No sensitive data, API keys or credentials in client-side code or responses. The site handles no customer data, sessions or personal information beyond what you type into the contact form.

Insecure Transport & Downgrade Attacks

TLS 1.2 and 1.3 only, with trusted certificate chains. No legacy protocols or weak ciphers, and every resource loads over a secure connection.

Accidental Exposure of Internal Systems

The demo is architecturally isolated from production. No backend systems, databases or internal services are reachable through it, so a compromise there cannot reach customer systems.

Architectural Isolation & Continuous Validation

It runs in complete isolation from production systems, customer data and operational infrastructure.

Network Isolation

  • Separate network segments and security groups
  • No connectivity to production environments
  • Dedicated hosting infrastructure

Data Separation

  • No customer data in demo environment
  • No access to production databases
  • Minimal data collection and retention

Continuous Monitoring

  • Automated vulnerability scanning
  • Regular security assessments
  • Proactive remediation workflows

Responsible Disclosure

Found something? Report it through our coordinated disclosure process. We acknowledge promptly, investigate thoroughly and credit researchers.

Report a vulnerability at security@axonyx.ai

Proxy Infrastructure

Threat Model & Security Posture

Axonyx operates a proxy-first architecture designed for defence-in-depth. Our publicly exposed inference proxy at proxy.axonyx.ai presents an intentionally minimal attack surface.

Proxy-First Security Model

The proxy sits between your organisation and the model providers. Every request passes policy enforcement, inspection and logging before it reaches an external model.

Defence-in-Depth Layers

  • Request authentication and authorization
  • Input validation and sanitization
  • Policy enforcement and guardrails
  • Response inspection and filtering
  • Comprehensive audit logging

Minimal Attack Surface

  • No administrative endpoints exposed publicly
  • No API specification disclosure
  • Limited service fingerprinting
  • Strict transport security enforcement
  • Rate limiting and abuse prevention

Key Threats Addressed

Unauthorised API Access

All requests require valid authentication tokens. Multi-factor authentication enforced for administrative access. Session management with automatic expiration and revocation.

Prompt Injection & Malicious Inputs

Advanced pattern detection identifies jailbreak attempts, system prompt manipulation, and instruction injection. Requests are blocked or escalated based on risk scoring.

Model Misuse & Policy Circumvention

Policy enforcement occurs at the proxy layer before requests reach models. Organizations define acceptable use policies, content restrictions, and data handling requirements.

Data Exfiltration via AI Responses

Response inspection detects sensitive data patterns including credentials, PII, and proprietary information. Responses containing restricted data are blocked or redacted.

Endpoint Discovery & Enumeration

Public endpoints expose only essential inference functionality. No API documentation, debug interfaces, or administrative paths are accessible without authentication.

Abuse of Inference Endpoints

Rate limiting prevents resource exhaustion and denial of service. Anomaly detection identifies unusual usage patterns. Automated throttling and blocking for abuse scenarios.

Security Assurance

The proxy infrastructure is validated continuously through several independent assessment methods.

Automated Security Scanning

  • Continuous API vulnerability assessment
  • SQL injection and GraphQL security testing
  • Transport layer security validation
  • Authentication and authorization testing

Manual Penetration Testing

  • Annual third-party penetration testing
  • Adversarial testing by security researchers
  • Application logic and business process review
  • Remediation verification and retesting

Recent scanning found no critical, high or medium risk findings across the public proxy. One low-risk fingerprinting finding is documented and assessed as non-exploitable, given the proxy is deliberately public.

Documentation

Audit & Reports

Security documentation to support your vendor assessments, with certification reports available as our programmes complete.

SOC 2 Report

Type II report will be available to customers under NDA once certification is complete.

Penetration Tests

Annual third-party penetration test summaries.

Security Questionnaires

Standard security questionnaire responses.

Request access to our compliance documentation through your customer success manager or contact our security team directly at security@axonyx.ai.

Bug Bounty

Responsible Disclosure

We welcome security researchers to help us maintain the security of our platform.

Security Bug Bounty Program

If you discover a security vulnerability, please report it to us responsibly. We are committed to working with security researchers to verify and address any potential vulnerabilities.

How to Report

  • Email security@axonyx.ai with details of the vulnerability
  • Provide sufficient information to reproduce the issue
  • Allow us reasonable time to address the issue before public disclosure

Our Commitment

  • Acknowledge receipt within 24 hours
  • Provide regular updates on our progress
  • Credit researchers who report valid vulnerabilities
Security questions?

Have questions
about security?

Our security team is here to answer any questions about our security practices, certification roadmap, or data protection measures.

Contact Security Team