Security

How we protect accounts, documents and extracted data in AxioExtract.

Last updated: 21 August 2026

1. Account security

AxioExtract uses token-based authentication. When you sign in, the service issues a secure session token that is stored in your browser and sent with every request. Passwords are never stored by us; authentication is handled by the underlying auth provider.

For your protection, the app signs you out automatically after five minutes of inactivity. A warning dialog appears 30 seconds beforehand, and the timer is paused while an extraction or other long-running task is in progress.

2. Two-factor authentication (2FA)

You can add a second step to sign-in from Workspace settings → Security. AxioExtract supports any TOTP authenticator app, including Google Authenticator, Authy and Microsoft Authenticator. Setting it up gives you eight single-use backup codes to download and keep somewhere safe.

Authenticator secrets are held by the auth provider, backup codes are stored only as salted hashes, and remembered-device tokens are hashed too — none of them can be read back out of the database. If you lose your authenticator app you can use a backup code, or have a six-digit code emailed to your account address, valid for ten minutes and one use only.

Five incorrect codes lock verification for 15 minutes. Every 2FA event — turned on or off, backup code used, emailed code used, device remembered or removed, and lock-outs — is recorded in workspace activity where you can review it. Choosing “remember this device” stores a secure http only cookie for 30 days; signing out or clearing your browser data removes it. Workspace owners and admins can make 2FA mandatory for everyone in their workspace.

Coming soon: single sign-on via SAML and OAuth (Okta, Microsoft Entra ID and Google Workspace) for Enterprise workspaces.

3. Workspace access controls

Every document, extraction job and result belongs to a workspace. Access is enforced at the database level by row-level security (RLS) policies, so a user can only read or modify data belonging to workspaces they are a member of.

Documents are stored in private storage buckets scoped to the organisation. They are not publicly accessible and cannot be downloaded by users outside the workspace.

4. Encryption

Data is encrypted in transit using TLS. Data at rest is encrypted using the encryption mechanisms provided by the managed cloud platform.

5. Data retention and deletion

Uploaded documents and extraction outputs are retained according to the storage settings in your workspace. Workspace owners and admins can configure an automatic document clean-up window, after which files and their extracted data are removed. You can also delete individual jobs and their outputs at any time.

Account data is kept for as long as your account is active and for a reasonable period afterwards to comply with legal obligations, resolve disputes and enforce our terms. See our Privacy Notice for more details.

6. AI processing and data handling

Some document types are processed using third-party AI vision and language models to interpret text, tables and drawings. Documents are sent to these providers only for the purpose of generating the structured extraction output you request.

We do not use your documents to train or improve third-party AI models. Where a deterministic parser is available for a document type (for example, the SPIR workbook template or CAD/BIM geometry readers), we use it in preference to sending content to an AI model.

7. Logging, monitoring and incident response

We log service activity for operational and security purposes. Logs are retained for a limited period and access is restricted to authorised staff.

Staff administrative actions are recorded in an audit log, including the actor, action, reason and timestamp. The platform maintains automated backups of application data.

8. Vulnerability reporting

If you discover a security issue, please report it to us at contact@axiometra.com. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to address it.

9. Limitations

No service can guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials, for choosing appropriate workspace members and roles, and for reviewing extracted data before use.

Axiometra Ltd

Registered in Scotland, company number SC892597

Registered office: 3 Prospect Place, Westhill, Aberdeenshire, AB32 6SY

VAT number: GB522727107

Email: contact@axiometra.com