Legal

Terms of Service

These terms govern use of Axiom's hosted self-service security scanner.

Last updated: August 29, 2026

The service

Axiom provides authenticated runtime-security scanning for application-controlled input, retrieval, tool, and output boundaries. Scanner responses include a verdict and an action determined by the organization mode and active deployment profile.

Axiom is one layer of a security program. It may produce false positives or false negatives and does not guarantee detection or prevention of every attack. Self-service plans do not include an uptime, response-time, or support SLA unless Axiom agrees to one in writing.

Accounts and API keys

You are responsible for accurate account information, authorized use of your account, and safeguarding credentials. Scanner API keys must be kept server-side and may be scoped to a deployment and its active security profile.

You must promptly revoke a key that is exposed or no longer required. You are responsible for implementing the scanner action returned to your application and for testing monitor and enforcement behavior before production use.

Plans and billing

Free includes up to 10,000 completed scanner requests per UTC calendar month. Premium is USD $20 per month and includes up to 100,000 completed scanner requests per UTC calendar month. Enterprise volume, architecture, support, and service terms are set by written agreement.

Stripe processes Premium subscriptions. Premium scanner entitlement is active only while the configured Premium subscription is active or trialing. If a plan reaches its monthly limit, the scanner may return HTTP 429. Subscription changes and cancellation are handled through the billing portal; fees already incurred are non-refundable except where required by law or agreed in writing.

Acceptable use

You may not use Axiom to violate law, compromise another system, interfere with the service, evade usage controls, distribute credentials, or develop attacks against Axiom or other users without prior written authorization.

Authorized security evaluation must stay within an agreed scope. Axiom may suspend access where necessary to address abuse, nonpayment, security risk, or material breach of these terms.

Data and intellectual property

You retain rights in content and configuration you submit. You grant Axiom the limited rights needed to process that material and provide, secure, and support the service. Axiom retains rights in its software, models, rulepacks, documentation, and service-generated security logic.

Data handling is described in the Privacy Policy and may be supplemented by an enterprise order form or data-processing agreement.

Disclaimers and liability

The self-service service is provided as available and without warranties to the maximum extent permitted by law. Axiom is not a substitute for secure design, access control, human review, compliance review, or incident response.

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages. Axiom's aggregate liability for the self-service service will not exceed the amount paid by you for that service during the twelve months before the event giving rise to the claim. Different limits may apply under a signed enterprise agreement.

Changes and governing terms

We may update these terms as the service changes. Material changes will be posted with an updated effective date. Continued use after an update constitutes acceptance where permitted by law.

These terms are governed by Ohio law, excluding conflict-of-law rules, unless a signed agreement states otherwise. Signed order forms and enterprise agreements control if they conflict with these self-service terms.

Contact

Questions about these terms can be sent to support@axiomsecurity.dev.