Security at Axys Analysis

How we protect your data, and how to report a vulnerability.

Reporting a vulnerability

If you believe you've found a security vulnerability in Axys Analysis, please report it to security@axysanalysis.com with the subject line “Security Disclosure”. We ask that you give us reasonable time to investigate and address the issue before public disclosure. We will acknowledge your report within 48 hours and keep you informed of our progress.

Our security practices

All data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to authorised personnel. We conduct regular dependency vulnerability scanning and maintain an audit log of all significant system events. Candidate personal data is retained for up to 12 months if a job never closes, or for 30 days after job closure for completed assessments (non-completed candidates are deleted immediately on closure), in line with our retention policy.

Scope

In scope: axysanalysis.com, app.axysanalysis.com, and the Axys Analysis API. Out of scope: third-party services we rely on (Supabase, Vercel, Anthropic, Stripe). Please report vulnerabilities in those services directly to their respective security teams.

Contact

Security disclosures: security@axysanalysis.com

General enquiries: hello@axysanalysis.com

Data protection: privacy@axysanalysis.com