AIXYRA
Security & Trust

Built for organizations that audit their vendors

A governance platform holds your most sensitive AI decisions — so it has to clear a higher bar than the systems it governs. Here is how AIXYRA protects your data. SOC 2 certification is in progress.

Enterprise identity & access

Single sign-on over SAML 2.0 and OIDC with your identity provider, SCIM 2.0 automated user provisioning and deprovisioning, and role-based access control throughout the platform. Direct sign-in requires a one-time code sent by email alongside the password.

Your data, kept private and separate

Every organization's governance data is isolated from every other's. Cross-organization access does not exist as a product feature, and administrative access paths are restricted and audited.

Encryption in transit and at rest

All traffic is encrypted with TLS. Stored credentials and secrets — identity provider secrets, cloud scanning credentials, model keys, integration tokens — receive field-level encryption with support for zero-downtime key rotation, are masked in every API response, and are never written to logs.

Tamper-evident audit trail

Every governance action is recorded in an append-only audit log that cannot be edited or silently deleted — enforced at the data layer, not just in application code. Retention defaults to seven years and is configurable per organization.

Controlled emergency access

Emergency (break-glass) access follows an explicit request, approval, and revocation workflow, with every step written to the immutable audit log — no invisible superuser paths.

Deployment on your terms

Run cloud-hosted, self-hosted, or hybrid. The self-hosted option supports fully air-gapped environments for government, defense, and other sovereignty-sensitive deployments.

Resilience and recovery

The managed service runs across more than one AWS region, with the database replicated to a standby and a rehearsed path for promoting it. Infrastructure is defined as code, so an environment can be rebuilt from the repository rather than from memory.

Privacy by default

The public website runs no third-party analytics or advertising trackers. In-product AI features can run on your own model endpoints, and optional data-scanning features require explicit, revocable consent.

Coordinated disclosure

Found a vulnerability? We publish a security.txt and respond to reports quickly. Contact us and we will work with you on coordinated disclosure.

Compliance Frameworks

  • EU AI Act
  • NIST AI RMF
  • ISO/IEC 42001

Deployment Models

  • AWS Cloud
  • Docker Self-Hosted
  • Hybrid Deployment

Security Posture

  • SOC 2 Certification in Progress
  • Your Data Kept Private & Separate

Have a security questionnaire?

We answer vendor security reviews as part of every enterprise evaluation. Reach us at [email protected] or request a demo.