Enterprise-grade security.
No compromises.

AxioGreen is designed for enterprise building portfolios where data integrity, access control, and regulatory compliance are non-negotiable. Here is exactly how we protect your data.

🔐

Authentication & SSO

AxioGreen uses Keycloak as the identity and access management layer — the same open-source IAM trusted by Red Hat, Airbus, and thousands of enterprises. Every login uses PKCE OAuth 2.0 with short-lived JWT access tokens and refresh token rotation.

  • PKCE OAuth 2.0 flow — no client secrets exposed in browser
  • JWT access tokens with configurable expiry
  • Silent SSO — seamless re-authentication without re-login
  • SAML 2.0 & OIDC integration for your corporate IdP
  • Multi-factor authentication (MFA) configurable per realm
  • Password reset via email with secure tokens
🛡

Authorisation & Access Control

Access is controlled by a granular role-based access control (RBAC) system. Admins assign roles per user — not just platform-wide but down to individual building level.

  • Roles: Admin, Administration, Workforce, AI Energy, Energy Declaration
  • Per-user building-level access restriction
  • Read-only access for stakeholders who need visibility without write permissions
  • Role changes take effect immediately — no cache lag
  • All role grants and revocations are audit-logged
🔒

Data Encryption

All data is encrypted in transit and at rest using industry-standard algorithms.

  • TLS 1.3 for all API and web traffic — no TLS 1.0/1.1 supported
  • AES-256 encryption for data at rest
  • HTTPS enforced with HSTS headers (max-age 31536000, includeSubDomains)
  • Strict Content Security Policy — prevents XSS injection
  • X-Content-Type-Options, X-Frame-Options, Referrer-Policy headers on all responses
  • Database connections encrypted with TLS certificates
🌍

Data Residency & GDPR

AxioGreen is built for European customers with EU data residency as the default. We are fully GDPR compliant and do not transfer personal data outside the European Economic Area.

  • All infrastructure hosted in EU data centres
  • Sweden-only data residency available on Enterprise plans
  • Data Processing Agreement (DPA) provided on request
  • Right to erasure supported — full data deletion on request
  • Data portability — full CSV/JSON export at any time
  • No third-party advertising or analytics trackers
📋

Audit Logging

Every significant action in the platform — building creation, user access changes, alarm acknowledgements, sensor threshold changes — is recorded in tamper-resistant audit logs.

  • Role grants and revocations logged with actor, timestamp, target
  • Alarm acknowledgements & resolutions logged with user + optional note
  • Sensor threshold changes logged portfolio-wide
  • Setup Wizard transactions logged as atomic operations
  • Modbus polling enable/disable logged per device
🔄

Infrastructure & Uptime

AxioGreen runs on containerised infrastructure with automated failover, daily backups, and a 99.9% SLA for Enterprise customers.

  • Docker-based containerisation with health monitoring
  • Automatic restart on container failure
  • Daily encrypted database backups with point-in-time recovery
  • 99.9% uptime SLA on Enterprise plans
  • Caddy reverse proxy with automatic TLS certificate renewal (Let's Encrypt)
  • Zero-downtime deployments via blue-green strategy

Found a vulnerability?

We take security seriously and appreciate responsible disclosure from the security community. If you believe you have found a security vulnerability in AxioGreen, please report it to us privately before public disclosure.

Send a detailed description to security@axiogreen.com. We will acknowledge receipt within 24 hours and aim to resolve validated issues within 30 days. We will credit researchers who report valid vulnerabilities in our security changelog.

Please do not perform automated scanning against production systems or attempt to access customer data. Test against your own account only.

Contact Security Team

Questions about security?

We'll provide a full security questionnaire, DPA, and architecture review for enterprise evaluations.

Talk to Us →