Skip to content
Security and compliance

Security built in from the first line of code, not bolted on later.

Axim is designed for the trust expectations of public-sector operations. Council data is isolated by design, encrypted in transit and at rest, kept in Australia, and fully auditable, with the day-to-day controls in the hands of your own administrators.

  • 100% Australian data residency
  • Designed against ISO 27001, IS18 and the Essential Eight
  • Sovereign AI by default
  • Seven-year audit trail

A detailed security and compliance briefing is available to councils and their advisors on request.

Security-first by design

The controls a council security team expects, in language the whole panel can follow.

ISO 27001, the Queensland IS18 policy, and the ACSC Essential Eight shaped Axim's architecture from the start rather than being retro-fitted. Here is what that means in practice.

Tenant isolation by design

Every council runs in its own separate database space. The platform cannot reach across into another council's data, because the boundary is enforced at the database itself rather than left to application rules to remember.

Three independent layers of protection

Behind-the-scenes services are not reachable from the public internet, they require a verified identity to talk to each other, and every request is then checked against what the user is allowed to do. All three have to hold before any data is reached.

Encrypted in transit and at rest

All traffic is protected with modern TLS, and stored data is encrypted. The most sensitive fields, such as tax file numbers and bank account details, carry a second layer of encryption so they cannot be read even from the raw database.

Access your administrators control

Permissions, roles, which modules are visible, and what each person can see are managed by your own administrators from a single screen. Routine access changes do not depend on raising a vendor ticket.

Accountable support access

Axim support staff hold no standing access to your data. When they need to help, they open a named, time-limited session with a recorded reason, and every action is written to an audit log you can see.

A complete, searchable audit trail

Every change to a record captures who made it, what changed, and when. Administrators can search and filter that history, and it is retained for seven years to support record-keeping and any later investigation.

Data residency and sovereignty

Your data stays in Australia, and so does the AI.

Sovereignty is a baseline expectation for councils, not an optional add-on. Axim is pinned to an Australian region from the database through to the AI layer.

What residency means in practice

Every part of the platform runs in Google Cloud's Sydney region. Finance, payroll, property, records, requests, and safety data is stored and processed in Australia.
AI is sovereign by default. Prompts run on Australian-hosted models unless your administrators deliberately choose an external provider.
If you opt in to an external AI provider, each request is classified for sensitivity and logged, so you keep a clean record of that decision.
Hosting sits with a provider that holds its own independent certifications, including ISO 27001, SOC 2, and IRAP.
Access control

Access your administrators control, without a vendor ticket

Permissions: the building blocks that decide who can read or change each kind of information.
Roles: permissions bundled into job-based roles such as Finance Manager, ready to use and yours to adjust.
Module visibility: switch off entire modules a team does not use, both in the interface and behind the scenes.
Data scopes: narrow what each person sees, so a team leader sees their own team rather than the whole organisation.
Per-person overrides: grant or withdraw an individual permission, with an optional expiry date.
Governed AI

AI with approval gates, redaction, and a full audit trail

Every AI task is opt-in. If your council does not want a particular task, it stays switched off.
Higher-impact tasks prepare a draft and wait for a named, authorised person to approve before anything changes.
Sensitive content is removed from AI output before it is stored.
Every run and every approval is recorded, so AI activity is as auditable as any other action.
Processing stays in Australia by default, with external providers used only if you choose to supply your own.
Secure delivery and resilience

A disciplined path from change to production, with recovery built in.

The way software is built and shipped is part of the security story. Axim's delivery pipeline is designed to keep that path tight and auditable.

How changes reach production safely

Every change is peer-reviewed and automatically tested before it can be released.
Deployments use short-lived, key-less credentials, so there are no long-lived keys to be leaked.
Card payments are handled by Stripe. Axim never stores card numbers, which keeps both the council and Axim out of card-data compliance scope.
Automated daily backups with point-in-time recovery, on managed infrastructure designed to withstand the loss of a data-centre zone.
Software dependencies are monitored and patched as part of routine maintenance.
Compliance direction

Aligned to the frameworks councils are asked about.

Axim has been built against three reference frameworks from the start: ISO/IEC 27001:2022, the Queensland Government IS18 information security policy, and the ACSC Essential Eight. The technical controls these frameworks expect are largely in place; the work remaining before formal certification is the policy and evidence layer.

The standards and obligations below are what Axim is designed and being assessed against. Until certificates are issued, treat them as directional alignment rather than a certification claim.

SOC 2 Type I pathwayAustralian Privacy Principles (APP)Notifiable Data Breaches (NDB) schemeASD Essential EightQueensland IS18 information securityPublic Records Act 2023 (Qld)WHS Act 2011
Common questions

What councils and their advisors ask first.

Short, direct answers to the questions that come up most often in procurement and security review.
Does our data leave Australia?

Not in normal operation. Core platform data is stored and processed in Google Cloud's Sydney region, and AI runs on Australian-hosted models by default. Data is only processed offshore if your administrators deliberately choose an external AI provider, and that choice is recorded.

Who can see our data?

Only the people your administrators invite; there is no self-signup. Axim support staff have no standing access. When they need to assist, they open a named, time-limited session that is fully recorded in an audit log you can review.

Can we use our own single sign-on (SSO)?

Yes. Councils can federate their existing identity provider, such as Microsoft Entra ID, Okta, or Google Workspace, using SAML 2.0 or OpenID Connect. Staff sign in with their normal corporate credentials, accounts are matched by email on first sign-in with no manual linking, and multi-factor authentication is enforced through your own provider's policies. Access stays invite-only, so only the people your administrators have provisioned can sign in. Automated directory provisioning (SCIM) is on the roadmap; today, accounts are provisioned by your administrators.

Is Axim certified to ISO 27001 or SOC 2?

Not yet. Axim has been designed against ISO/IEC 27001:2022, the Queensland IS18 information security policy, and the ACSC Essential Eight from the outset, and is on a defined pathway towards formal certification. We are happy to walk your security team through the current control status and roadmap.

Can we get our data out if we leave?

Yes. Axim uses open formats and a standard database, with no proprietary lock-in. Your data can be exported at any time and is returned to you at the end of a contract.

How do you keep AI under control?

AI sits behind a governance layer. Tasks are opt-in, higher-impact actions require a person to approve a prepared draft, sensitive content is redacted before storage, and every run is audited. By default all processing stays in Australia.

What happens if there is a security incident?

Axim operates under the breach-notification obligations of the Privacy Act 1988. In the event of an eligible data breach, the OAIC and affected individuals are notified as required, and affected councils are kept informed throughout.

Next step

See Axim in the context of your organisation

Book a guided walkthrough focused on the areas that matter to your team, whether that is finance and rates, records and SharePoint, asset operations, or the migration path from your current platform.

We can tailor the discussion around your current operating model, governance requirements, and transition priorities.