Falcon Axiom

Trust grows through clear boundaries.

Understand what applies to the marketing website, what remains planned for product workloads and where to report a security concern.

Security starts with the boundary of the work.

Falcon Axiom’s security programme is organised around identity, data paths, changes and operations. The public website and marketing enquiry route run separately from product project workloads, so a product placement decision does not describe where marketing information is processed.

For a product engagement, review the controls and evidence for the actual deployment: who can sign in, which roles can reach each resource, how sensitive information is protected, who controls keys, where project data is placed and how changes or incidents are handled. Product direction is a starting point for that review; the engagement establishes the verified service boundary.

Identity and authority

Review authentication strength, multi-factor authentication (MFA), role scope, workload identity and privileged approvals for the selected environment. Confirm which people and services can perform each action.

Data protection and keys

Confirm encryption in transit and at rest, key custody, sensitive-data access and evidence for the actual service. No particular algorithm or key-control arrangement is promised by this overview.

Project-country placement

The planned model associates each product project with a selected country cell. India is the initial focus; other country destinations require their own provider, operational and legal readiness. This does not make marketing storage India-resident.

Governed change and evidence

Review how changes are scoped, approved and recorded, which actor can apply them and how the resulting evidence is retained for the engagement.

Assurance is built through reviewable evidence.

Designed for compliance readiness. Evaluation in progress. Not certified.

Assurance programme

SOC 2, ISO 27001 and HIPAA expectations are evaluation references for programme planning. They are not certifications or a statement that every related control is already implemented.

Processing agreements

Discuss workload-specific processing needs, including whether a data-processing agreement (DPA) or business associate agreement (BAA) applies, with legal@falconaxiom.com. Availability and scope are confirmed through reviewed written terms.

Service protection and availability

Review DDoS resilience, abuse handling, operational evidence and support scope for the specific deployment and its service-edge boundary. No RPO, RTO, uptime guarantee or recovery service level is published on this page.

Shared responsibility

The engagement defines the service boundary. Customers remain responsible for their application authorization, account choices, data use and external integrations under their control.

Review the operational fit for each deployment.

A useful security review connects technical controls to the people and procedures that operate them. For each engagement, agree who owns account access and incident communication, how changes are reviewed, which evidence is available, how third-party integrations are bounded, and where backups and recovery procedures apply.

Retention, restoration, service levels and country availability depend on the actual design and written engagement. Confirm the evidence and operating responsibilities for the selected workload before setting an objective or commitment.

Report a vulnerability or security concern.

Send a concise report to security@falconaxiom.com. Include the affected public hostname or product surface, the steps needed to reproduce the observation and a safe way to follow up. Do not include passwords, private keys, customer records or unrelated sensitive data.

The team will use the information to understand and assess the report and follow up through the safe channel you provide. Do not access another person’s data, disrupt a service, persist access or test protected product systems without explicit written authorization. If you encounter an exposed secret, do not repeat or use it; identify its location and share only what is needed for triage.

Security questions, answered.

Is Falcon Axiom certified to SOC 2, ISO 27001 or HIPAA?

No. These are evaluation references for the assurance programme. Falcon Axiom is not certified.

Does the marketing website use the planned product-country cell?

No. Marketing website and enquiry processing are separate from product project-country placement and may involve international delivery.

Can I test a protected product service?

Only with explicit written authorization and a defined scope. Public information or a working URL does not grant permission.

What should a vulnerability report contain?

The affected public hostname or product surface, safe reproducible steps and a way to follow up. Keep credentials and customer records out of the report.

Security and trust contacts.

Use the channel that matches your question.

Security reports

Report a suspected vulnerability or security concern.

Email security

Machine-readable disclosure details

Read the published vulnerability contact file.

Open security.txt

Legal and grievance

Ask about terms or raise a grievance.

Email legal