Security & data handling

What we can tell you today — honestly.

No fake badges, no invented certifications. This page reflects our actual security posture, including the gaps we haven't closed yet.

Where is data stored?

Self-hosted PostgreSQL (via Supabase) on a dedicated VPS — our sole environment for both development and production. Physical data residency is not yet formally documented; ask us directly if this is a requirement for your evaluation.

Tenant isolation

Every Axceed product owns its own schema and tenancy — no product reads another product's data directly. Row Level Security is enforced on every table, and cross-product access happens only over an authenticated REST API, never a shared database connection.

Encryption

All data in transit is encrypted (TLS). Application-level secrets (API keys, service credentials) are encrypted at rest via Supabase Vault. Disk- and backup-level encryption is not yet independently verified — we say this plainly rather than assume it.

Access control

Role-based access is enforced server-side on every request, not just hidden in the UI. Axceed staff accessing a customer environment use short-lived, individually-audited access — never a standing shared account.

Multi-factor authentication

Supported today (TOTP). Enforcement is rolling out staff-side first; customer-side enforcement is in progress, not yet mandatory everywhere.

Backups

Daily backups, 30-day retention. Regular restore-verification testing is required by our own internal standard but not yet evidenced across the whole portfolio — we're not going to claim more confidence in this than we currently have.

Certifications

None yet. No SOC 2 or ISO 27001 certification exists today. We are actively building the management-system artifacts (scope, policies, risk treatment, management review) an ISO 27001 program requires, visible in Cosmos's own ISMS module — but we have not completed a formal audit, and we won't claim otherwise to win a deal.

Data deletion (PDPA)

Deletion requests are actionable — contact us and we will process a deletion within a reasonable response window. This is currently a manual process, not yet a self-service control.

Questions we haven't answered here

If your security questionnaire needs something more specific than this page — network architecture, a formal DPA, pen-test history — email us and we'll answer directly rather than guess at what you need.