Operator
← Operator for enterprise

Security & Trust

Security is not a feature. It's the foundation.

Operator is built for teams whose code can't leave the building. Here is exactly how it's protected, where it runs, and where we are on compliance — stated plainly, with no overstatement.

How a request is governed

Every request passes through policy before it reaches a model.

Sign-in and identity, then role and policy, then the model, then your data — each stage enforced, each action recorded. Nothing reaches a model or your repository that policy hasn't cleared.

01 · Identity

Shield

Zero-trust sign-in — device-flow (RFC 8628) and SSO. Tokens are bearer headers, never in URLs.

02 · Policy

Tower

Role- and attribute-based access, and per-action approval for anything irreversible or outward-facing.

03 · Evidence

Knox

An append-only audit chain — every decision leaves evidence that can't be quietly rewritten.

Controls

What your security team asks for.

01

Sovereign hosting

Models built and hosted by AXE on its own hardware — hosted, on-prem, or fully air-gapped. Not rented from a third-party frontier API.

02

SSO & device-flow auth

Google / Microsoft SSO and the RFC 8628 device grant. SAML / SCIM provisioning available on request.

03

Per-action approval

Irreversible and outward-facing actions are gated behind explicit approval; approval never carries across contexts.

04

Tiered access & keys

Admin vs. member tool tiers; scoped API keys shown once, revocable instantly. Secrets ride as headers, never URLs.

05

Audit trail

Actions are recorded to an append-only chain (Knox, Ed25519 + ML-DSA-65) so activity is reviewable and tamper-evident.

06

No training on your data

Your code and prompts are not used to train models by default. Canadian data residency.

Data handling

Where it runsAXE-owned infrastructure (Canadian-resident), your datacentre, or fully air-gapped.
Data residencyCanada. No reliance on the US CLOUD Act, FISA, or Patriot Act jurisdictions.
Model trainingYour code and prompts are not used to train models by default.
Secrets in transitBearer tokens in Authorization headers; never in URLs, query strings, or logs.
API keysScoped per project, shown once (hash stored), revocable instantly.
Access modelSSO, role/attribute-based policy, per-action approval, tiered tool access.
AuditAppend-only, tamper-evident chain of actions (Knox).

Compliance status

Stated plainly — in progress is marked in progress.

PIPEDACompliant.
ITSG-33Aligned. 11 baseline controls; full mapping available under NDA.
FIPS 140-2In progress (Level 1).
Protected BAssessment planned. PBMM gap analysis complete.
SOC 2 Type IIPlanned. Audit engagement scheduled Q3 2026.

Need the control mapping, an assessment letter, or a questionnaire answered? Request documents →

Sovereignty

canadian.data.residency no.cloud.act no.fisa no.patriot.act air-gap.capable on-prem.capable

We don't rent AI infrastructure. We build systems organizations own outright — deployed on their hardware, governed by their policies, answerable only to them.

Responsible disclosure

Found a vulnerability? Email james@virul.co — privately first, with repro steps. We acknowledge within two business days and will agree a disclosure timeline. Good-faith research is welcome; don't access data that isn't yours.

Bring it to your security review.

We'll answer the questionnaire

Request documents → Overview