Security & Trust

We hold ourselves to the standard we assess against.

You are being asked to give an outside advisor visibility into sensitive systems. This page states exactly how that access is scoped, used, and retired — written to be forwarded to whoever must approve it.

Access

The least we can do the work with.

Read-only and least-privilege

Engagements request scoped, read-only credentials and nothing further. No write access, no standing administrative rights, and no persistent session beyond the engagement window.

Written authorisation first

No system is examined without a signed authorisation naming the environment, the scopes, the time window, and the officer granting it. Access is always something you extend deliberately.

You execute the changes

We produce findings and a sequenced remediation list. Your team makes the changes. Nothing in your environment is altered on your behalf — the risk of doing so belongs on your side of the keyboard.

Revocation is yours

Access can be withdrawn at any moment, for any reason, without discussion. For continuous monitoring, that control sits permanently with you.

Data

What we hold, and for how long.

Storage

Findings and collected artefacts are encrypted at rest. Your source data is not duplicated beyond what the engagement requires.

Retention

Assessment and audit material is destroyed thirty days after delivery. Continuous monitoring data is held on a rolling ninety-day window.

Confidentiality

Every engagement runs under a mutual non-disclosure agreement and a written services agreement. Client names are never published without explicit permission.

Conduct

Boundaries we state before you ask.

Assessment, not intrusion

Our engagements examine configuration, telemetry, and architecture. They are not penetration tests. Active exploitation — including demonstrating an attack against a live system — requires a separate, explicitly authorised scope, and we will tell you so rather than drift into it.

Advisory, not legal counsel

We identify regulatory exposure and map findings to the frameworks auditors apply. We do not render legal opinions, and we will say plainly when a question belongs with your counsel.

Insured and accountable

Axiomeer carries professional (errors and omissions) and cyber liability cover. Findings are advisory and point-in-time; we state that in the agreement rather than in a footnote.

Questionnaires welcome

Send your vendor security questionnaire. We answer them quickly and completely — reviewing them for clients is part of the work, so we know what a good answer looks like.

Before anything is signed

Have your security team ask us anything.

We are happy to walk your IT or security function through precisely what an engagement touches — in advance, and without obligation.