Security & Compliance
A factual overview of current Axiom security controls. No certification or compliance status is implied unless stated in a signed agreement.
Architecture
Management, SMB, and DNS roles can be separated onto dedicated Linux servers. Policy push payloads are encrypted with ChaCha20-Poly1305 and authenticated using the node enrollment secret; HTTPS can protect the management channel.
Offline verification
License files are verified locally using a bundled public key. The private signing key is kept outside customer deployments.
Access control
The product provides local administrative authentication, optional LDAP/Active Directory login, node enrollment, role-separated services, and audit and diagnostic records.
Disclosure
Report suspected vulnerabilities to [email protected] with reproduction details and affected versions. Do not include live customer secrets in the initial report.
Last updated: July 2026