Controls we can implement — described honestly.
Every engagement records which controls apply, how they are configured, who owns them and where a limitation exists.

Grouped by access, data and operations.
What applies depends on your platforms and the sensitivity of the workflow. Nothing here is assumed to be in place by default.
- Access controls
Named accounts, no shared logins for workflow administration.
- Role-based permissions
Users see and do only what their role requires.
- Restricted prompt and configuration access
Workflow logic is changed by authorised people only.
- Environment separation
Test and live separated where your systems support it.
- Approved data sources
A documented list of what the workflow may read.
- Data-retention settings
Retention period agreed per workflow, not left to a default.
- Encryption in transit
Standard transport encryption between the systems involved.
- Encryption at rest where implemented
Dependent on the platforms in use; stated per engagement.
- Customer-controlled deletion requests
A route to request removal of specific records.
- Secure secrets management
Credentials held in a managed store, never in shared documents.
- Audit logging
A record of workflow activity and approvals, retained per policy.
- Security testing
Checks appropriate to the scope, performed before go-live.
- Incident response
An agreed path for stopping a workflow, notifying and correcting.
- Vendor review
A written record of the providers involved and what they process.
- Data-processing agreements
Executed where the engagement requires them.

A control without a named owner is a control that quietly lapses.
Responsibility for each item is recorded in the scope of work and confirmed at handover.
Who is responsible for what
- Axiomora
Configuring agreed controls, documenting them, and flagging anything we cannot implement in your environment.
- Client
Owning the systems, approving the data sources, managing user accounts and deciding retention.
- Shared
Incident handling, access reviews and any change to scope that affects data handling.
No unverified certifications
We do not claim compliance with ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR certification or UAE government security standards unless independently verified for the specific engagement.
Where your procurement process requires evidence, tell us during scoping. We will state plainly what can be evidenced, what can be contractually committed and what cannot.
Report a concern to management@axiomora.online. Include the workflow name and what you observed; we will confirm receipt and the next step.

Written down, or it did not happen.
At handover you receive the configured control list, the approved data sources, the retention settings, the access list and the known limitations for the workflow.
That document is the thing that lets a new IT manager, auditor or department head understand the workflow without calling us.