Security
- Encryption. Data is encrypted in transit with TLS, and at rest.
- Access control. Access to production systems is role-based and least-privilege, requires multi-factor authentication, is logged, is reviewed periodically, and is removed when someone leaves.
- Separation. Customer data is logically separated, and automated tests check that one account cannot reach another's data.
- Payments. Card details go directly to Stripe. Axis never sees or stores a full card number.
- Backups. Encrypted, with restoration tested.
- Monitoring. Access to production is logged and retained for 12 months.
- Vendors. Every company that may touch personal data is under written data protection terms and is listed on the Subprocessor page.
Where your data lives
Axis is operated from the United States and customer data is stored there. Our messaging provider Brevo operates in the European Union. International transfers are covered in the Privacy Policy and, for business customers, in the Data Processing Addendum.
If something goes wrong
We maintain a documented incident response process with defined roles and escalation. If a breach affects personal data we notify affected customers and the relevant authorities where the law requires, without undue delay, and for business customers within 48 hours of becoming aware, as the Data Processing Addendum requires.
Reporting a vulnerability
If you have found a security issue, tell us at security@axismarketing.ai. Include what you found, how to reproduce it, and what impact you think it has. We aim to acknowledge within 2 business days and to keep you updated until it is resolved.
Safe harbor
Where you comply with this policy, act in good faith, and allow Axis reasonable time to remediate the issue before disclosure, Axis will not pursue legal action against you and will treat your research as authorized.
Permitted testing
- Test only against your own account.
- Stop as soon as you have confirmed a vulnerability exists.
- Give us reasonable time to fix it before telling anyone else.
Prohibited testing
- Access, modify or delete data belonging to anyone else.
- Degrade the Service, including denial of service and load testing.
- Use social engineering, phishing or physical attacks against our people or offices.
- Publish details of an unfixed issue.
We do not currently run a paid bounty program. We will credit researchers who ask to be credited.