Security built in from the first line of code, not bolted on later.
Axim is designed for the trust expectations of public-sector operations. Council data is isolated by design, encrypted in transit and at rest, kept in Australia, and fully auditable, with the day-to-day controls in the hands of your own administrators.
- 100% Australian data residency
- Designed against ISO 27001, IS18 and the Essential Eight
- Sovereign AI by default
- Seven-year audit trail
A detailed security and compliance briefing is available to councils and their advisors on request.
The controls a council security team expects, in language the whole panel can follow.
Tenant isolation by design
Every council runs in its own separate database space. The platform cannot reach across into another council's data, because the boundary is enforced at the database itself rather than left to application rules to remember.
Three independent layers of protection
Behind-the-scenes services are not reachable from the public internet, they require a verified identity to talk to each other, and every request is then checked against what the user is allowed to do. All three have to hold before any data is reached.
Encrypted in transit and at rest
All traffic is protected with modern TLS, and stored data is encrypted. The most sensitive fields, such as tax file numbers and bank account details, carry a second layer of encryption so they cannot be read even from the raw database.
Access your administrators control
Permissions, roles, which modules are visible, and what each person can see are managed by your own administrators from a single screen. Routine access changes do not depend on raising a vendor ticket.
Accountable support access
Axim support staff hold no standing access to your data. When they need to help, they open a named, time-limited session with a recorded reason, and every action is written to an audit log you can see.
A complete, searchable audit trail
Every change to a record captures who made it, what changed, and when. Administrators can search and filter that history, and it is retained for seven years to support record-keeping and any later investigation.
Your data stays in Australia, and so does the AI.
What residency means in practice
Access your administrators control, without a vendor ticket
AI with approval gates, redaction, and a full audit trail
A disciplined path from change to production, with recovery built in.
How changes reach production safely
Aligned to the frameworks councils are asked about.
Axim has been built against three reference frameworks from the start: ISO/IEC 27001:2022, the Queensland Government IS18 information security policy, and the ACSC Essential Eight. The technical controls these frameworks expect are largely in place; the work remaining before formal certification is the policy and evidence layer.
The standards and obligations below are what Axim is designed and being assessed against. Until certificates are issued, treat them as directional alignment rather than a certification claim.
What councils and their advisors ask first.
Does our data leave Australia?
Not in normal operation. Core platform data is stored and processed in Google Cloud's Sydney region, and AI runs on Australian-hosted models by default. Data is only processed offshore if your administrators deliberately choose an external AI provider, and that choice is recorded.
Who can see our data?
Only the people your administrators invite; there is no self-signup. Axim support staff have no standing access. When they need to assist, they open a named, time-limited session that is fully recorded in an audit log you can review.
Can we use our own single sign-on (SSO)?
Yes. Councils can federate their existing identity provider, such as Microsoft Entra ID, Okta, or Google Workspace, using SAML 2.0 or OpenID Connect. Staff sign in with their normal corporate credentials, accounts are matched by email on first sign-in with no manual linking, and multi-factor authentication is enforced through your own provider's policies. Access stays invite-only, so only the people your administrators have provisioned can sign in. Automated directory provisioning (SCIM) is on the roadmap; today, accounts are provisioned by your administrators.
Is Axim certified to ISO 27001 or SOC 2?
Not yet. Axim has been designed against ISO/IEC 27001:2022, the Queensland IS18 information security policy, and the ACSC Essential Eight from the outset, and is on a defined pathway towards formal certification. We are happy to walk your security team through the current control status and roadmap.
Can we get our data out if we leave?
Yes. Axim uses open formats and a standard database, with no proprietary lock-in. Your data can be exported at any time and is returned to you at the end of a contract.
How do you keep AI under control?
AI sits behind a governance layer. Tasks are opt-in, higher-impact actions require a person to approve a prepared draft, sensitive content is redacted before storage, and every run is audited. By default all processing stays in Australia.
What happens if there is a security incident?
Axim operates under the breach-notification obligations of the Privacy Act 1988. In the event of an eligible data breach, the OAIC and affected individuals are notified as required, and affected councils are kept informed throughout.
See Axim in the context of your organisation
Book a guided walkthrough focused on the areas that matter to your team, whether that is finance and rates, records and SharePoint, asset operations, or the migration path from your current platform.
We can tailor the discussion around your current operating model, governance requirements, and transition priorities.