Security at AXO Signal

Security is an integral part of the design, development and operation of AXO Signal.


We maintain technical and organisational controls designed to protect the confidentiality, integrity and availability of information processed through our platform.


Encryption


AXO Signal uses industry-standard encryption protocols to protect data in transit.


Data at rest is protected using appropriate security controls and encryption where supported and appropriate to the relevant systems.


Hosting and infrastructure


AXO Signal is hosted using established cloud infrastructure providers.


Primary infrastructure: AWS

Primary hosting region: United Kingdom


Our infrastructure is designed to support secure, resilient and scalable operation.


Access control


Access to production systems and customer information is restricted according to operational requirements.


Controls include, where appropriate:


  • role-based access;
  • least-privilege principles;
  • secure authentication;
  • privileged-access restrictions;
  • access logging; and
  • periodic access review.


Authentication


AXO Signal implements authentication controls designed to protect customer accounts and prevent unauthorised access.


Customers are responsible for protecting their credentials and notifying us immediately where compromise is suspected.


Application security


Security considerations form part of the AXO Signal development lifecycle.


Our practices include appropriate:


  • code review;
  • dependency management;
  • vulnerability remediation;
  • environment separation;
  • access controls;
  • logging and monitoring; and
  • security testing.


Incident response


AXO Signal maintains procedures for identifying, assessing, containing and responding to security incidents.


Where an incident affects personal data, notification will be handled in accordance with applicable data protection law and contractual obligations.


Business continuity


We maintain appropriate backup, resilience and recovery measures designed to reduce the impact of infrastructure failures and operational incidents.


Vulnerability reporting


We welcome responsible reports from security researchers and users who believe they have identified a security vulnerability.


Reports should be sent to: platform@axosignal.io


Please include sufficient information to reproduce and assess the issue.


Responsible disclosure


We ask researchers to:


  • avoid accessing data unnecessarily;
  • avoid disrupting our services;
  • avoid modifying or deleting information;
  • protect information discovered during research; and
  • provide reasonable time for investigation and remediation before public disclosure.



We will investigate legitimate reports and engage constructively with researchers acting responsibly and in good faith.