Conservative by design.

Security posture · Last updated 5 June 2026

Built around limited authority. Axiom is designed around least privilege, scoped permissions, revocation, and request-level evidence. We do not claim certifications, accreditations, or regulatory approvals we do not hold.

Our approach

Axiom sits between an AI agent’s intent and the movement of money. That is a position of trust, so we treat restraint as a feature. The product is designed to grant the least authority necessary, to keep a human able to intervene, and to leave a clear record of every decision. Where we are uncertain, we choose the more conservative option.

Limited permissions

Agents receive only the authority you explicitly grant. Permission scope is narrow, expressed deliberately, and revocable: you can withdraw or change it at any time. There is no implicit or standing authority. If a request falls outside the granted scope, Axiom is built to stop it before money moves.

Evidence without secrets

Every request Axiom checks is recorded so a decision can be explained after the fact. That evidence is designed to capture what was decided and why, without storing secrets, API keys, or sensitive credentials in the record itself. The goal is an audit trail you can hand to a colleague or reviewer without creating a new place for secrets to leak.

Scoped deployment

Axiom can be deployed through scoped pilots tied to a real workflow, so teams can introduce agent permissions with controls, evidence, and operational review from day one. The goal is deliberate deployment into real operations, not open-ended access without guardrails.

Security commitments

We try to be clear about the security properties we are designing for:

  • Authority is explicit, scoped, and revocable rather than broad or standing.
  • Requests are checked before execution, with evidence designed to explain what was checked and decided.
  • Evidence is designed not to expose secrets, API keys, or sensitive credentials.
  • Axiom is being built with SOC 2-aligned control principles in mind, including least privilege, revocation, and auditable workflows. We are not SOC 2 certified today.
If you need a deeper controls discussion for a real workflow, we cover that directly during pilot evaluation.

Reporting an issue

If you believe you have found a security vulnerability, we want to hear from you. Please follow our responsible disclosure guidance and email security@axiomgo.ai.

Talk to us about a pilot →