Data & Security

Controls we can implement — described honestly.

Every engagement records which controls apply, how they are configured, who owns them and where a limitation exists.

Colleagues reviewing system user access permissions on a screen in an office
Control set

Grouped by access, data and operations.

What applies depends on your platforms and the sensitivity of the workflow. Nothing here is assumed to be in place by default.

Access
  • Access controls

    Named accounts, no shared logins for workflow administration.

  • Role-based permissions

    Users see and do only what their role requires.

  • Restricted prompt and configuration access

    Workflow logic is changed by authorised people only.

  • Environment separation

    Test and live separated where your systems support it.

Data
  • Approved data sources

    A documented list of what the workflow may read.

  • Data-retention settings

    Retention period agreed per workflow, not left to a default.

  • Encryption in transit

    Standard transport encryption between the systems involved.

  • Encryption at rest where implemented

    Dependent on the platforms in use; stated per engagement.

  • Customer-controlled deletion requests

    A route to request removal of specific records.

Operations
  • Secure secrets management

    Credentials held in a managed store, never in shared documents.

  • Audit logging

    A record of workflow activity and approvals, retained per policy.

  • Security testing

    Checks appropriate to the scope, performed before go-live.

  • Incident response

    An agreed path for stopping a workflow, notifying and correcting.

  • Vendor review

    A written record of the providers involved and what they process.

  • Data-processing agreements

    Executed where the engagement requires them.

Two colleagues at a shared desk reviewing an access list and workflow monitoring notes
Ownership

A control without a named owner is a control that quietly lapses.

Responsibility for each item is recorded in the scope of work and confirmed at handover.

Who is responsible for what

  • Axiomora

    Configuring agreed controls, documenting them, and flagging anything we cannot implement in your environment.

  • Client

    Owning the systems, approving the data sources, managing user accounts and deciding retention.

  • Shared

    Incident handling, access reviews and any change to scope that affects data handling.

No unverified certifications

We do not claim compliance with ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR certification or UAE government security standards unless independently verified for the specific engagement.

Where your procurement process requires evidence, tell us during scoping. We will state plainly what can be evidenced, what can be contractually committed and what cannot.

Security or privacy contact

Report a concern to management@axiomora.online. Include the workflow name and what you observed; we will confirm receipt and the next step.

Colleagues reviewing a printed data-handling policy document and marking approvals with a pen
Documentation

Written down, or it did not happen.

At handover you receive the configured control list, the approved data sources, the retention settings, the access list and the known limitations for the workflow.

That document is the thing that lets a new IT manager, auditor or department head understand the workflow without calling us.