الأمان والامتثال
الأمان والامتثال في أكسيكس
تعمل أكسيكس تكنولوجيز كشركة SaaS مؤسسية عالمية متعددة المنتجات. الأمان والخصوصية والامتثال مدمجة في كل منصة — من ERP وHCM إلى CyberDragon.ai وAxix Hawk.
آخر تحديث: يونيو 2026
الأمان والامتثال على مستوى المؤسسات
- جاهز لـ SOC 2 Type II
- متوافق مع ISO 27001
- متوافق مع GDPR
- اتفاقية توفر 99.9%
- تشفير AES 256 بت
- إقامة بيانات متعددة المناطق
Data Encryption Standards
All customer data is encrypted in transit and at rest using industry-standard protocols.
- TLS 1.2+ for all API and web traffic
- 256-bit AES encryption at rest for databases and object storage
- AES-256-GCM for license signing keys on Axix Hawk
- Customer-managed encryption keys available on enterprise plans
Infrastructure Security
Axix SaaS platforms are hosted on hardened cloud infrastructure with defense-in-depth controls.
- Primary hosting on AWS with Azure and Google Cloud options for private cloud tenants
- Network segmentation, WAF, and DDoS protection at the edge
- Automated patching and vulnerability scanning on managed infrastructure
- Multi-region deployment with contractual data residency SLAs
- 99.9% uptime SLA on self-serve SaaS products
Penetration Testing — Powered by CyberDragon VAPT
We eat our own dog food. Axix runs continuous agentic penetration testing on our own production and staging environments using CyberDragon VAPT — the same platform we sell to customers.
- Continuous agentic reconnaissance and vulnerability assessment
- Remediation tracking integrated with Axix engineering workflows
- Annual third-party penetration tests by independent assessors
- Customer-facing VAPT reports available on CyberDragon Professional plans
GDPR & Data Processing
Axix processes personal data in accordance with GDPR and applicable regional privacy laws.
- Data Processing Agreements (DPA) available for all enterprise customers
- Right to access, rectification, erasure, and portability supported
- Sub-processor list published and updated on request
- EU/UK data residency options on Private Cloud deployments
- Privacy policy and cookie controls at /legal/privacy
Vulnerability Disclosure Policy
We welcome responsible security research from the community.
- Report vulnerabilities to security@axixtechnologies.com
- Please include steps to reproduce, impact assessment, and affected product
- We aim to acknowledge reports within 48 hours
- Coordinated disclosure — we request 90 days before public disclosure
- Researchers acting in good faith will not face legal action
Bug Bounty Program
Axix maintains a responsible disclosure and recognition program for validated security findings.
- Scope: *.axixtechnologies.com production SaaS properties and published APIs
- Out of scope: social engineering, physical attacks, third-party integrations without authorization
- Rewards based on severity (Critical, High, Medium) — contact security team for current tiers
- Duplicate reports and known issues are not eligible
- Enterprise customers may request private bug bounty scope for dedicated tenants