Skip to main content
HomeSecurity
Security and data controls

Recruitment data needs more than a polished login screen.

AxamyOne uses tenant-bound access, role permissions, private document workflows, audit history and guarded service connections to protect the operational records agencies rely on.

  • No certification claims without evidence
  • Tenant-bound authority
  • Service-side document controls

Due-diligence principle

This page describes controls implemented in the current AxamyOne codebase and operational design. It does not claim ISO 27001, SOC 2, Cyber Essentials, a specific data-centre region, an uptime guarantee or a backup frequency that has not been separately evidenced.

Access and separation

Authority is checked against the company and the requested action.

Access is not based only on knowing a workspace URL. Identity, active membership, tenant scope, lifecycle status and module permission are used to guard data and workflow operations.

Authenticated workspace access

Staff access is tied to an authenticated account and active tenant membership.

Tenant separation

Canonical records are tenant-bound and database row-level security is enforced for protected data.

Role and module permissions

Consultant, manager, compliance, finance and administration access can be scoped to the modules needed for the role.

Lifecycle controls

Trial, paid, suspended and offboarding states are checked before protected mutations and automation.

Server-owned authority

Sensitive operations use guarded server or database functions rather than trusting browser-supplied tenant identity.

Conflict protection

Version and compare-and-set controls protect supported records from silent concurrent overwrites.

Private documents

Uploaded evidence follows a controlled lifecycle.

Candidate and staff document workflows bind uploads to the tenant, candidate and document record. File size, declared type and inspected bytes are validated before evidence becomes available.

  • Private object paths
  • Bounded upload size
  • File-type and byte inspection
  • Checksum verification where exposed
  • Malware scan queue
  • Quarantine until validated
  • Expired-upload cleanup
  • Exact-path deletion
AxamyOne compliance workspace showing candidate document checks and review status
Auditability and data handling

Important actions should leave operational evidence.

AxamyOne maintains tenant-scoped records for supported audit, email-delivery, public-form and document workflows, with bounded service operations and idempotency protection where duplicate delivery would be risky.

Audit history

Supported record changes and workflow events are written to tenant-scoped audit history for later review.

Delivery ledgers

Automated and system email paths use durable identity and delivery records to reduce unsafe duplicate sends.

Exports and offboarding

Company export and offboarding workflows are permission-gated and designed around exact tenant scope.

Microsoft 365

Customer recruitment mail and AxamyOne system mail remain separate.

Supported customer messages use the verified Microsoft organisation connection and authorised mailbox routing configured for that workspace. AxamyOne technical and system notifications use a separate controlled pipeline.

  • Organisation-level Microsoft connection
  • Authorised users and shared mailboxes
  • Tenant-bound mailbox selection
  • Verified purpose routing
  • Durable delivery identity
  • Separate system notifications

Data ownership and portability

Customer data remains scoped to the customer workspace. Export and deletion requests follow authorised operational processes; the exact commercial, retention and assistance terms should be confirmed in the customer agreement and privacy documentation.

Read the privacy notice
Operational resilience

Security also includes recovery and visibility.

The repository includes database and storage backup tooling, restoration workflows, technical monitoring and production-readiness checks. Current customer due diligence should request the latest evidence for the production environment rather than relying on a static marketing promise.

Backup tooling

Database and private-storage backup jobs are maintained separately from the live application workflow.

Restore process

Restoration tooling and drill procedures support validating that protected backup outputs can be used.

Technical monitoring

Health endpoints and technical monitoring cover core service availability and worker status.

Environment isolation

Production and staging configuration are checked to prevent unproved cross-environment data access.

Security headers

The public deployment defines transport, content, framing, referrer and browser-permission controls.

Release gates

Automated tests and production-readiness scripts check migrations, configuration and guarded workflows before cutover.

Security questions

Ask for evidence, not badges.

Does AxamyOne claim ISO 27001, SOC 2 or Cyber Essentials?

No certification claim is made on this page. If a certification becomes available, it should be supported by current evidence and scope.

Are company workspaces separated?

Yes. Protected canonical data is tenant-bound, database row-level security is enforced and sensitive service operations verify tenant membership and permission.

How are uploaded documents handled?

Supported direct-upload workflows use private tenant-bound paths, bounded files, server-side validation and malware scanning before final availability.

Can customers export their data?

AxamyOne includes an authorised company export workflow. The exact export coverage and offboarding assistance should be confirmed against the current implementation and customer agreement.

Where is the data hosted and how often is it backed up?

Those answers depend on the current contracted production environment and operational schedule. Request the latest deployment and backup evidence during due diligence rather than relying on an unverified general statement.

Bring your due-diligence questions.

We’ll answer against the current product and production evidence rather than giving you generic security wording.

Discuss security and implementation