Security
Your audit records, protected and provably yours.
You are trusting Axiospec with the records that prove your quality program. Here is exactly how that data is stored, kept private, proven tamper-evident, and returned to you whenever you want it. Every point below is something the platform does today.
Where your data lives
- Hosted on Amazon Web Services in the United States (us-east-1).
- Encrypted in transit everywhere: the app and API are served only over HTTPS (TLS).
- The production database is encrypted at rest and is private, with no public internet access.
- Each workspace is isolated: your records are scoped to your tenant and never shared across customers.
Built to prove integrity
- Every committed calibration is written to a tamper-evident, hash-chained ledger with a timestamp and the user who recorded it.
- Anyone with access can verify the full chain in one click and see exactly where, if ever, a record was changed.
- Optional maker-checker approvals require a second person to sign off before a record is final.
- Role-based permissions control who can view, record, and approve, and internal support actions are written to an audit log.
How people sign in
- Two-factor authentication with any authenticator app is available to every user, on every plan including Free.
- Single sign-on for the whole workspace over OpenID Connect or SAML, so accounts follow your existing identity provider.
- Restrict sign-in to your own email domains and set the role new people receive by default.
- Admins can require single sign-on for everyone, with a fallback path so an administrator cannot be locked out of their own workspace.
Your data stays yours
- Export a complete, audit-ready pack of your records at any time, in formats an auditor accepts.
- No lock-in and no per-seat fees for the people who keep your records complete.
- If you close your account, your data is retained for a window so you can still export it, as described in our Terms.
- Import yourself from CSV, Excel, GAGEpack, or GAGEtrak, or hand it off for free white-glove migration.
Reliability and recovery
- The production database takes automated daily backups with a 14-day retention window.
- Deletion protection is enabled on the production database to guard against accidental loss.
- Records are versioned on the ledger: superseded entries are never silently overwritten, they are chained.
Documentation for your review process
Adopting a calibration system usually means a security review, a software validation record, and an assessor who wants to see the output. These are written for those readers, and they state plainly what Axiospec does not have as well as what it does.
- Security and Data Handling (PDF) For an IT or security reviewer: hosting and region, encryption, network isolation, tenant separation, access control, backups, subprocessors, and the gaps we have not closed.
- Software Validation Summary (PDF) Input to your own validation record, not a substitute for it. Intended use, the data-integrity controls and how they are enforced, and a checklist you can run and sign in your workspace.
- Audit Evidence Guide (PDF) What an assessor actually receives: the contents of the one-click audit pack, how as-found and as-left readings appear, and how corrections show without erasing history.
Need something these do not cover, such as a completed security questionnaire? Email support@axiospec.com.
Have a security question or a report?
If your team needs to review how we handle data before you commit records, or you want to report a vulnerability, email us at support@axiospec.com. We reply within one business day. Axiospec is built by CaliTech LLC in Knoxville, Tennessee.