Security & compliance
How we handle security and access.
A practical account of how infrastructure, access, and client data are handled across engagements — not a certification claim.
Last updated: February 2026
Infrastructure
Client infrastructure is provisioned as code (Terraform) inside the client's own cloud accounts wherever the engagement calls for it, rather than a shared multi-tenant environment we control. Every change to production infrastructure is reviewed in a pull request before it is applied.
Access control
Access to client systems is granted per engagement, scoped to the individuals actually doing the work, and revoked at the end of the engagement or when a team member rotates off it. Where the client supports it, we use single sign-on and short-lived credentials instead of shared logins.
Data handling
We collect only what a project requires. Contact-form and project-scoping submissions (name, work email, organisation, and project description) are used to respond to the enquiry and are not sold or shared with third parties for marketing purposes. See our privacy policy for the full detail on what we collect and how it's stored.
Application security
Dependency and vulnerability scanning runs as part of our standard CI/CD pipeline configuration. Security-relevant findings are triaged and, where they affect a client system, disclosed directly to that client rather than held for a periodic report.
Certifications
We do not currently hold ISO 27001 or an equivalent third-party security certification. Where a client's procurement process requires a specific certification or compliance framework, tell us during scoping and we'll give you a direct answer on whether we can meet it.
Reporting a security issue
If you believe you've found a security issue affecting AxioGrid or a system we operate, email admin@axiogridsystems.com with details. We aim to acknowledge reports within two business days.