Security at AXO Signal
Security is an integral part of the design, development and operation of AXO Signal.
We maintain technical and organisational controls designed to protect the confidentiality, integrity and availability of information processed through our platform.
Encryption
AXO Signal uses industry-standard encryption protocols to protect data in transit.
Data at rest is protected using appropriate security controls and encryption where supported and appropriate to the relevant systems.
Hosting and infrastructure
AXO Signal is hosted using established cloud infrastructure providers.
Primary infrastructure: AWS
Primary hosting region: United Kingdom
Our infrastructure is designed to support secure, resilient and scalable operation.
Access control
Access to production systems and customer information is restricted according to operational requirements.
Controls include, where appropriate:
- role-based access;
- least-privilege principles;
- secure authentication;
- privileged-access restrictions;
- access logging; and
- periodic access review.
Authentication
AXO Signal implements authentication controls designed to protect customer accounts and prevent unauthorised access.
Customers are responsible for protecting their credentials and notifying us immediately where compromise is suspected.
Application security
Security considerations form part of the AXO Signal development lifecycle.
Our practices include appropriate:
- code review;
- dependency management;
- vulnerability remediation;
- environment separation;
- access controls;
- logging and monitoring; and
- security testing.
Incident response
AXO Signal maintains procedures for identifying, assessing, containing and responding to security incidents.
Where an incident affects personal data, notification will be handled in accordance with applicable data protection law and contractual obligations.
Business continuity
We maintain appropriate backup, resilience and recovery measures designed to reduce the impact of infrastructure failures and operational incidents.
Vulnerability reporting
We welcome responsible reports from security researchers and users who believe they have identified a security vulnerability.
Reports should be sent to: platform@axosignal.io
Please include sufficient information to reproduce and assess the issue.
Responsible disclosure
We ask researchers to:
- avoid accessing data unnecessarily;
- avoid disrupting our services;
- avoid modifying or deleting information;
- protect information discovered during research; and
- provide reasonable time for investigation and remediation before public disclosure.
We will investigate legitimate reports and engage constructively with researchers acting responsibly and in good faith.
