Security & data governance

Security review begins before data transfer.

A credible B2B deployment requires clear current controls, explicit deployment-specific responsibilities and a strict public no-health-data boundary.

Azure-hosted baselineAuthenticated accessVersion traceabilityDeployment-specific review
01 / Current technical baseline

Documented controls - Explicit deployment boundaries.

Security claims are limited to controls that can be documented and reviewed. Deployment-specific obligations are defined before sensitive data enter a partner workflow.

Current baseline

Microsoft Azure environment

AXIS currently operates in Microsoft Azure. The exact services, regions and deployment responsibilities are defined during qualified partner review.

Current + deployment-specific

Authenticated access

Platform access is authenticated. Role definitions, privileges, organization boundaries and offboarding will be defined and documented for each qualified deployment.

Current baseline

Versioned engine output

Outputs retain module and version context, supporting technical traceability.

Deployment-specific

US healthcare package

Data roles, BAAs, subprocessors, retention and secure transfer depend on the partner and use case.

02 / Qualified pilot review

Define the complete data lifecycle.

Security and privacy must be scoped before identifiable or sensitive data enter any pilot environment.

Data classification

Identify whether data are identifiable, de-identified, pseudonymized or aggregate.

Contractual roles

Define controller, processor, covered entity, business associate or other applicable roles.

Access model

Specify users, organizations, permissions, authentication and offboarding.

Transfer & storage

Define channels, regions, encryption controls and approved subprocessors.

Retention & deletion

Document operational periods, backups, deletion and evidence of completion.

Incident response

Define detection, escalation, notification and responsibilities.

No blanket compliance claims

This website does not present AXIS as universally “HIPAA compliant,” “FDA exempt,” CE-marked or clinically validated. Status depends on the exact function, intended use, contracts, deployment and jurisdiction.