Security and Trust at Axiom Advisory Global
Axiom Advisory Global builds software for construction and related industries, including our flagship platform and other current and future services (collectively, the "Services"). This Trust Center summarises our approach to security, privacy, and compliance, and links to the full set of legal documents that govern our relationship with Customers.
Our Legal Documents
Privacy Policy
How we collect, use, and protect personal dataTerms of Service
The agreement governing use of our ServicesSub-processors
Third parties who help us deliver the ServicesData Processing Addendum
Terms governing our processing of Customer DataCookie Policy
The limited, essential cookies we useSecurity Measures
We apply layered, industry-standard security practices across the Services:
Encryption
Data is encrypted in transit and at rest using industry-standard encryption protocols.
Access Controls
Internal access to Customer Data is limited to authorised personnel on a least-privilege, need-to-know basis.
Authentication
Account access is protected by secure authentication mechanisms and automatic session expiry.
Monitoring
Our infrastructure is monitored continuously, with automated alerting and an established incident response process.
Rate Limiting
Automated abuse-prevention and rate-limiting controls protect the Services from misuse.
Audit Logging
Administrative and access actions are recorded on an append-only basis to support accountability and investigation.
Certifications and Compliance
We are working toward SOC 2 Type II certification and will publish updates on this page as that process progresses. We do not claim any certification we do not currently hold. Our practices are designed to align with the principles of the GDPR, the Australian Privacy Act 1988 (Australian Privacy Principles 1 to 13), and the CCPA/CPRA, as described in our Privacy Policy.
Data Residency
Our primary hosting region is Australia. Supporting infrastructure may be located in additional regions where necessary to provide the Services reliably and securely, subject to the international transfer safeguards described in our Privacy Policy and Data Processing Addendum.
Incident Response
We maintain an internal incident response process for identifying, containing, and remediating security events. Where a confirmed incident affects Customer Data, we notify affected Customers without undue delay, and in any event within 24 hours of becoming aware, in accordance with our Data Processing Addendum.
Contact for Security Inquiries
To report a security concern, request security documentation, or ask about our compliance posture, contact us at admin@axiomadvisory.org.
Vendor and Sub-processor Oversight
Every third party engaged to support the Services is subject to a written agreement covering confidentiality, data protection, and security obligations consistent with this Trust Center and our Data Processing Addendum. We review our sub-processor relationships periodically and maintain a current, publicly available list on our Sub-processors page.
Business Continuity
Customer Data is backed up regularly as part of our operational practices, with defined retention periods described in our Privacy Policy. Our infrastructure is designed with redundancy in mind, so that a localised failure does not result in extended service disruption.
Responsible Disclosure
If you believe you have identified a security vulnerability in the Services, we encourage you to report it to us at admin@axiomadvisory.org before disclosing it publicly. We will acknowledge reports promptly and work with you in good faith to investigate and remediate confirmed issues.