Trust

Security & Compliance

A factual overview of current Axiom security controls. No certification or compliance status is implied unless stated in a signed agreement.

Architecture

Management, SMB, and DNS roles can be separated onto dedicated Linux servers. Policy push payloads are encrypted with ChaCha20-Poly1305 and authenticated using the node enrollment secret; HTTPS can protect the management channel.

Offline verification

License files are verified locally using a bundled public key. The private signing key is kept outside customer deployments.

Access control

The product provides local administrative authentication, optional LDAP/Active Directory login, node enrollment, role-separated services, and audit and diagnostic records.

Disclosure

Report suspected vulnerabilities to [email protected] with reproduction details and affected versions. Do not include live customer secrets in the initial report.

Last updated: July 2026