Trust centre · Security
Security
This page is split in two on purpose: measures that protect your traffic today, and the formal artifacts a commercial security review expects, which are being finalized for launch. We state which is which, and we claim no certifications.
In place today
What protects your traffic now
| Measure | What it is |
|---|---|
| Transport encryption | TLS 1.3, terminated at the EU edge. |
| Edge → inference link | Encrypted private WireGuard tunnel between the EEA edge and the inference hardware. |
| Prompt handling | Zero prompt retention: prompts and completions are processed in memory and discarded when the request completes — never written to disk, logged or retained. |
| Tenant isolation | Enforced row-level security in the platform database. |
| Console authentication | OIDC via Atom9 Identity, with server-side sessions. Detail: Atom9 integration. |
| Internal service calls | Service-to-service requests are cryptographically authenticated. |
| Hardware | Inference runs on hardware AxForge owns and operates — no third-party compute for inference. Detail: data residency. |
| Operator access | Access to production systems is limited to named operators. |
- Network topology and facility detail are deliberately not published here. Detailed physical and technical measures live in a private TOMs annex, available under NDA/DPA — talk to an engineer to request it.
Pre-release posture
Being finalized for commercial launch
AxForge is pre-release. The following documents and evidence are being finalized for commercial launch — until each one ships, we do not claim it.
| Item | What it will provide |
|---|---|
| Formal incident-response runbook | Documented roles, escalation paths and timelines for security and privacy incidents. Reporting works today — see incidents & reporting. |
| External security testing | Independent testing of the platform and edge, on a stated cadence. |
| Deletion-verification evidence | Evidence that deletion runs remove exactly what the retention schedule says they remove. |
| Backup-recovery drills | Rehearsed restores of the metadata stores, with documented outcomes. |
| Formal patch/vulnerability program | A documented patching cadence and vulnerability-handling process. |
| MFA policy documentation | Documented multi-factor authentication requirements for operator access. |
- Every claim on this page is a concrete, checkable property rather than a badge. Formal third-party certifications and audits are planned as the service moves to production; the security posture is published factually here and in the TOMs annex. The GDPR-sensitive workloads page explains how the provider side and the customer side of GDPR fit together.
Related
Nearby in the trust centre
Trust centre
Data residency & sovereignty
Retention & deletion
Incidents & reporting
Subprocessor register
Data Processing Agreement (draft)
Privacy policy
Version 0.1 (launch draft) · Effective 2026-08-26
- 2026-08-26 — first published version of this page.