About Axiom

Security in the path of critical protocols.

Axiom is built for organizations that want to keep file services and DNS under their own operational control while adding centralized policy, evidence, and enforcement.

Why Axiom

Protect the path clients already use

SMB file services and DNS are foundational network dependencies. Axiom adds dedicated enforcement points without requiring software on every endpoint.

Clients connect to an SMB Proxy Node instead of the backend file server. The node relays the session, inspects file-write evidence, and records what policy decided. A separate DNS Security Node evaluates lookups before forwarding approved queries upstream.

A central Management Server brings both services into one operational view while keeping the data plane inside the customer's network.

When scale or availability requires more nodes, Management can organize SMB and DNS data planes into cluster groups. Replicas inherit the source service template, policy, and reputation while preserving host-specific network settings.

Design principles

Built for controlled enterprise networks

Defensible defaults

New DNS deployments do not block broad categories by surprise, and data-plane nodes fail predictably when Management is unavailable.

Protocol-aware enforcement

Axiom works in the SMB and DNS paths, where it can collect protocol evidence and apply policy close to the protected service.

Cluster-managed roles

SMB and DNS replicas inherit shared service configuration while keeping local NIC and listener addressing under host control.

Offline-ready operation

Core enforcement and license verification can operate without direct internet access, including in restricted and air-gapped networks.

Deployment model

Three roles, a scale-out data plane

Production guidance is to separate roles and add cluster-managed SMB or DNS replicas where capacity and availability require them. A single-server lab role remains available for evaluation.

Management Server

The administrative Web UI, node registry, policy control plane, reputation database, licensing state, audit view, and support diagnostics.

SMB Proxy Node

An inline reverse proxy that relays SMB2/SMB3, inspects write streams, calculates file hashes, and enforces configured policy.

DNS Security Node

A forwarding and caching resolver that evaluates domain policy, serves local records, and reaches only the upstream resolvers selected by the administrator.

Evaluate Axiom

Plan a deployment around your network.

Review the installation guides or discuss topology, firewall rules, and air-gap requirements with the team.