Axiforge Tech Ltd
Security & Privacy
Our products handle real user data. Here is exactly how we protect it across every product we ship.
Your data stays yours
Axiforge Tech products process user data ephemerally where possible. Message bodies, personal inputs, and sensitive content are never stored beyond what is required for the service to function.
OAuth only — no passwords
Products that connect to third-party services (e.g. Gmail) use OAuth 2.0 exclusively. We never see or store your account passwords.
Encryption in transit and at rest
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). API endpoints are protected by rate limiting and WAF rules.
GDPR & UK GDPR compliant
Axiforge Tech Ltd is a UK-registered company. All products are compliant with UK GDPR and the Data Protection Act 2018. Data is processed in EU/UK regions only.
SOC 2 Type II (in progress)
We are currently working toward SOC 2 Type II certification. Our security controls follow the AICPA Trust Services Criteria across all products.
Right to erasure
Users can request deletion of their account and all associated data at any time. Deletion requests are processed immediately and are irreversible.
Report a vulnerability
Found a security issue? Please disclose responsibly by emailing security@axiforge.co.uk. We aim to respond within 24 hours and will acknowledge responsible disclosures publicly (if desired).