Everything a security review asks for, already published.
No portal, no NDA, no call first. The security overview, the subprocessor list with regions, the full data inventory and every retention window are on this site right now. We hold no certification, and that is on this page too.
- Where does our data live?Every location published, with the exceptions namedPublished
- Who can reach a run artifact?An authorisation check, then a link scoped to that one runPublished
- Do you train AI models on our data?No. Commercial APIs that do not train, secrets scrubbed firstPublished
- How long do you keep it?Twelve windows, each enforced by a scheduled jobPublished
- Who else processes it?Every subprocessor, what it handles, and its regionPublished
- Is there a management system behind this?ISMS approved 26 August 2026. 93 controls, 23 scored risksPublished
- Do you hold a SOC 2 report?No. All 33 Common Criteria are mapped, but no auditor is engagedNot held
- Do you support single sign-on?No. SSO and SCIM are next on the roadmap, not shippedNot held
The programme
A management system, not a badge.
We hold no certificate and no report, and we claim neither. What we have instead is an operating record with dates on it, so you can judge it rather than take our word for it.
- 26 Aug 2026
- ISMS approved, and operating since
- 93
- Annex A controls in a Statement of Applicability
- 23
- Scored risks with named owners, reviewed quarterly
- 33 of 33
- SOC 2 Common Criteria mapped, with 0 gaps
- 45s
- Production restore, tested end to end and logged
- None
- Certificates or reports held. No auditor engaged
Behind those figures: a top-level information security policy and twelve sub-policies, all approved and dated; a named Security Owner; quarterly access and management reviews that have been performed rather than scheduled; and a Record of Processing Activities under Article 30. Our ICO data protection fee registration was submitted on 28 August 2026.
Controls
What is in place, and where it is enforced.
The last column is the one that matters. A control nobody can point to in the running system is a claim, not a control.
| Control | Where it is enforced | State |
|---|---|---|
| Encryption in transit | TLS on every connection, browser to platform to integration | In place |
| Encryption at rest | AES-256 by our providers, verified rather than assumed | In place |
| Execution credentials | AES-256-GCM in the application, decrypted only to run your tests | In place |
| Tenant isolation | Queries scoped to your organisation, cross-boundary requests refused | In place |
| Artifact access | Authorisation check, then a signed link scoped to a single run | In place |
| Role-based access | Owner, admin, member and viewer, checked on every request | In place |
| Two-factor authentication | Authenticator app with backup codes. Required for admins, in code | In place |
| Audit trail | Append-only, 12 months, purged nightly, outlives a deleted account | In place |
| Secret and PII scrubbing | Stripped from content before any AI call leaves the platform | In place |
| Private applications | Local agent, outbound only, one-time pairing codes, no inbound ports | In place |
| Vulnerability management | Dependency scanning, review before release, commit secret scanning | In place |
| Backup and restore | Automated backups, and a production restore tested end to end | In place |
| Single sign-on and SCIM | Not offered. On the roadmap, and said here rather than discovered later | Not held |
Protected access
Every artifact passes an access check.
Screenshots, videos, and traces are never public. Each request is checked against your organisation and role, then served through a short-lived signed link scoped to a single run, so access cannot be shared or replayed later.
- Tenant isolationData is scoped to your organisation, and any request that reaches across a boundary is refused.
- Authorisation on every requestAccess to a run and its artifacts is checked against your role before anything is served.
- Short-lived signed linksArtifact URLs expire quickly and cannot be reused or shared to grant standing access.
Artifact requested
Run #4821 · checkout screenshot
Authorisation check
Organisation and role verified
Signed link issued
Scoped to this run only
Access granted for this run only.
Our approach
How we think about your data.
Four commitments that shape how AxonQA is built and operated.
Your data remains yours
Your requirements, test cases, automation code, run results, and artifacts belong to you. We never sell your data, and we never use it to train AI models. It exists to serve your team and no one else.
AI with controlled context
AI features work on a task basis. Failure analysis, for example, uses the failed step and the context relevant to it, not your whole workspace. Secrets and PII are scrubbed before content reaches any model, and AI usage is metered per plan so consumption stays visible.
Private app support
Applications on private networks stay private. The AxonQA local agent runs inside your environment and connects outbound only, so there are no inbound ports to open and no public exposure. Pairing uses one-time codes, and device keys are stored hashed.
Human control
AI accelerates the work while people stay in charge. Generated tests, healing fixes, and risky assistant actions are reviewable, the assistant asks a clarifying question instead of guessing, and destructive actions always require your explicit confirmation.
Data location
Where your data lives.
Named locations for every kind of data we hold, and the places it is not, in the same breath.
- ApplicationVercel, serverless functions in Dublin
- Primary databaseSupabase PostgreSQL, European Union (Ireland)
- Screenshots and run artifactsCloudflare R2, Western Europe
- Test executionCloud runners in our EU and US regions
- Private applicationsThe local agent, inside your own network
And where it does not
- Test execution may run in either our EU or our US region.
- Our AI and email providers are based in the United States.
- The artifact bucket is not bound to R2 optional EU jurisdiction, so this is where the data is placed rather than a contractual guarantee that it cannot move. We would rather draw that distinction than let you assume the stronger one.
Accountability
Who operates the platform.
AxonQA is operated by a small team, and the controls below exist so that fact is a matter of record rather than a matter of trust.
- Every change is attributableCode and ISMS decisions alike live in version control, timestamped and attributed. An auditor can sample them rather than take our word for the sequence of events.
- The audit log cannot be editedIt is append-only and it outlives a deleted account, because a security record that could be erased on request would not be a security record.
- Administrative access requires a second factorEnforced in code rather than by policy, so it holds whether or not anyone is watching.
- The infrastructure controls are not ours to bypassHosting, database, storage and execution run on providers whose own controls sit outside our unilateral control.
- Recovery is tested, not assumedA production restore has been performed end to end and logged, not written down as a plan and left there.
Compliance and documents
Read the documents, do not request them.
Our privacy policy, terms, security overview and subprocessor list are all published in full. Only the Data Processing Agreement is sent on request, because it is signed.
- Privacy PolicyHow we collect, use, and protect personal data, and the rights you have over it.
- Terms of ServiceThe terms that govern use of AxonQA, including what you can point it at.
- SubprocessorsEvery provider that processes data on our behalf, what each handles, and its region.
- Data Processing AgreementOur commitments as a data processor, for customers who need one in place.
- Security OverviewA deeper walkthrough of our controls, infrastructure, and operational practices.
What we do not have
Named here so you do not have to discover any of it in a security review three weeks in.
- ISO 27001 certificateNot held. The management system runs; the certification audit is planned
- SOC 2 reportNot held. Criteria mapped in full, no auditor engaged, Type I planned first
- Independent penetration testNot yet performed. Scheduled
- Internal ISMS auditNot yet performed. Scheduled
- Single sign-on and SCIMNot offered. Next on the roadmap
We hold neither an ISO 27001 certificate nor a SOC 2 report, and we claim neither. What we have instead is an operating record you can read: an information security management system approved on 26 August 2026 and running since, all 33 SOC 2 Common Criteria mapped to the controls that satisfy them with 0 gaps, and every partial control listed with an owner. No auditor has been engaged and no report exists.
Found a security issue? Report it to security@axonqa.com. We investigate every report and ask for reasonable time to remediate before public disclosure.
Security FAQ
Common questions, answered directly.
Straight answers about how AxonQA handles your data, your applications, and AI.
Questions about security?
The overview, the subprocessor list and the full data inventory are published. Send us your questionnaire and we will complete it.