Legal

Privacy Policy

This policy describes how the hosted Axiom service processes account, billing, scanner, and operational information.

Last updated: August 29, 2026

Information we process

Account data includes your email address, authentication identifiers, organization membership, and support communications.

Billing data includes Stripe customer and subscription identifiers and plan status. Axiom does not store full payment-card details.

Scanner data includes request content hashes, scanner decisions, reason codes, security context supplied by your application, timing, and rulepack, model, and policy versions. Hosted scanner organizations default to bounded, redacted content excerpts; hash-only or explicitly opted-in bounded full excerpts may be configured separately.

Website and infrastructure logs may include IP address, browser or request metadata, cookies needed for authentication, and operational diagnostics.

How we use information

We use information to authenticate users, provide and secure the scanner, enforce plan limits, process subscriptions, populate the dashboard, troubleshoot incidents, prevent abuse, and respond to support requests.

Ordinary customer traffic is not automatically added to model training. Separate accuracy-feedback participation is off by default. When explicitly enabled, only redacted events with human disposition may become eligible for controlled offline evaluation or model-improvement workflows.

Service providers and storage

The hosted service currently uses Amazon Web Services for the scanner, Vercel for the website, Supabase for authentication and website metadata, and Stripe for subscription billing. These providers process information only as needed to supply their services to Axiom.

Information is retained for service operation, security, dispute resolution, and legal obligations. Contractual customers may agree to specific retention or deployment terms. Contact us to request access, correction, export, or deletion; some records may be retained where legally or operationally required.

Security and customer choices

Axiom uses encrypted transport, access controls, and hashed API-key storage. Plaintext scanner keys are displayed once at creation and are not stored by the website.

Customers control which application boundaries are sent to Axiom and should avoid sending content that is unnecessary for the security decision. API keys must remain server-side and should be revoked when no longer needed.

Contact

Questions and privacy requests can be sent to support@axiomsecurity.dev.