Request a demo

Trust

What your security review needs, in one place.

Everything on this page describes the production environment as it is built today, not a target state. Each control is defined in version-controlled infrastructure and asserted from live state at deploy time. If you need a document rather than a summary, request it on the Documents tab and we will send it dated.

At a glance

EU only. All processing and storage in AWS eu-west-3, Paris. GDPR. Research use only. A data processing agreement is signed per engagement, before any data moves.

On HDS, stated precisely.

The French HDS regime covers six hosting activities. Our infrastructure provider is certified on five of them. The sixth, administration and operation of the system that holds the health data, is excluded from their certificate, and that activity is ours. We are not HDS certified on it.

What follows from that, plainly: this environment is appropriate for research data that the controller has determined to be anonymised with respect to Axiome. Where a pilot needs to hold identifiable French care-origin data under our operation, the answer is deployment into your establishment's own infrastructure, not a certificate we do not hold.

We would rather you read that here than discover it in a questionnaire.

Controls

Each row describes the production environment as deployed. Where a control is enforced by infrastructure rather than by procedure, that is stated.

Infrastructure

Control As built
Data residency AWS eu-west-3, Paris. Compute, databases, object storage, keys and logs all in region
Encryption at rest Single customer-managed key across databases, cache, object storage and disk
Encryption in transit HTTPS only, TLS 1.2 or higher, HSTS on the public endpoint
Network isolation Three-tier network, default deny. Databases, cache and message broker reachable only from the application tier. No data port exposed to the internet
Object storage Private buckets, public access blocked, encrypted with the managed key. Browser uploads restricted to the application origin

Access

Control As built
Operator access to production Keyless, through a managed session service. No SSH key in the environment, with session and command records
Application credentials Short-lived, obtained from instance metadata. No long-lived access keys in the running environment
Least privilege Each workload is scoped to its own secrets, its own storage and a single encryption key. No wildcard access
Secrets Encrypted parameter store, per environment. No secrets in source control or in generated reports
Separation between organisations Enforced server side and fail closed. A request reaching outside your organisation returns nothing rather than a filtered result
Roles Held per workspace and per project. Access for anyone outside your organisation is explicit, scoped, and revoked in one operation

Change control and evidence

Control As built
Infrastructure as code The entire environment is defined in version-controlled infrastructure with remote state. One sanctioned manual step, a DNS record
Deployment evidence Each deployment generates an infrastructure evidence record from live state. If the record cannot be generated, the deployment fails
Migration qualification Each database migration produces an installation, operation and performance qualification record. A migration is not complete until they pass
Environment sign-off Recorded with reviewer and date before an engagement begins

Controls described by hand drift from the system they describe. These are produced by the deployment itself, and the deployment does not finish without them.

What we do

Keep everything in the EU. Encrypt it at rest and in transit. Hold your interpretation record inside your own environment. Sign a data processing agreement before anything moves, and an NDA before that if you prefer. Give you a final export and then delete, with a certificate, at the end of an engagement.

What we never do

  • Pool, copy or aggregate your record across customers
  • Use your data or your interpretations as training material
  • Charge for export, at any time, for any reason
  • Apply an exit fee, a notice condition or a negotiation to your leaving
  • Hold your record in a proprietary format. Open documented formats, including provenance chains, rules, evidence bindings and the audit trail
  • Process anything outside the EU
  • Offer Axiome for diagnostic use. It is research use only

Subprocessors

Subprocessor Purpose Location
Amazon Web Services Platform hosting, all customer data France, eu-west-3
Hostinger Marketing website only. No customer data EU
Microsoft 365 Business email and calendar. Contact form correspondence EU

Named again in each data processing agreement. We will tell you before this list changes.

Documents

Document Access
Privacy policy Open
Mentions légales Open
HDS posture statement, hosting environment On request
Data processing agreement On request
Continuity and reversibility terms On request, issued dated
Architecture overview for security review On request

Requested documents are issued dated rather than left as standing PDFs, because what they describe changes as the platform is built. Request one on the contact form.

Security questions

Where is our data hosted?

AWS eu-west-3 in Paris. Compute, databases, object storage, encryption keys and logs are all in region. Nothing is processed or stored outside the EU.

Who at Axiome can access our environment?

Production access is keyless and session-recorded. Access is on a named basis for operational necessity, and every session and command is recorded.

Is our data used to train models or improve the product for others?

No. Your interpretation record stays in your environment and is never pooled across customers or used as training material.

What happens to our data if we stop working with you?

You export everything first, in open documented formats, at no charge. Then we delete and issue a certificate. There is no exit fee and no condition attached.

Can we host it ourselves?

Deployment into your own infrastructure is available as a scoped project rather than a configuration switch. Ask and we will scope it.

Do you hold certifications?

GDPR compliance, and the HDS position stated on the Overview tab. Where we hold a certification in future it will be published here with its scope and date.

Is Axiome a medical device?

No. Research use only, not for diagnostic use.

Can external collaborators be given access?

Yes, explicitly and per project, scoped to what you grant. Access is granted and revoked in one place.

How do we raise a security question or report an issue?

security@axiomebio.com.

Start with your own data.

We can work from your existing pipeline outputs, in your infrastructure. We can sign an NDA before anything is shared.

EU-hosted on HDS-certified infrastructureGDPRResearch use only (RUO)We reply within two business days