AxiomInfinity
Trust & Compliance

We hold ourselves to the same standards we recommend for clients.

Security, privacy, and compliance aren't things we bolt on at the end. They're how we operate from day one of every engagement.

Certifications & Standards

Our compliance posture.

ISO 27001 Aligned
Information security management framework
SOC 2 Ready
Type I assessment in progress (2026)
DPDP Act 2023 & Rules 2025 Compliant
DPDP Rules 2025 fully in force
GDPR Aware
EU data protection obligations acknowledged
HIPAA Aligned
For US healthcare sector engagements
ISO 9001 Aligned
Quality management processes
DPDP Act 2023

India's Digital Personal Data Protection Act — our commitments.

As a Data Fiduciary operating in India, Axiom Infinity is fully compliant with the Digital Personal Data Protection Act 2023 read with the DPDP Rules 2025. We process personal data only with explicit, specific consent and only for the purposes stated at the time of collection.

Our appointed Grievance Officer responds to all privacy inquiries with a 48-hour acknowledgment and 15-day resolution SLA. Data Principals may exercise their rights at any time by emailing privacy@axiominfinity.net.

Our DPDP Obligations Checklist

  • Clear notice to data principals before collection
  • Specific, informed, revocable consent mechanisms
  • Data Principal rights: access, correction, erasure
  • 48h acknowledgment and 15-day resolution SLA for requests
  • Appointed Grievance Officer (privacy@axiominfinity.net)
  • 72-hour breach notification to DPBI and affected principals
  • Cross-border transfer safeguards (India ↔ USA)
  • No data collected from persons under 18
  • Registered Consent Manager protocols implemented
Security Architecture

How we protect our own infrastructure.

TLS 1.3 Everywhere

All communications encrypted with TLS 1.3 minimum. HSTS preload registered. CAA DNS records restrict certificate issuance.

Zero-Trust Network Access

Internal services not exposed to the public internet. mTLS between services. Employee access via hardware FIDO2 keys.

WAF + DDoS Protection

Cloudflare WAF with OWASP CRS paranoia level 2. Bot Fight Mode enabled. Rate limiting on all public APIs.

Incident Response

72-hour breach notification to regulators and affected parties. Incident Response Retainer with pre-defined escalation paths.

Vulnerability Management

Continuous vulnerability scanning. External penetration test annually. Critical patches applied within 48 hours of disclosure.

Vendor Security

All sub-processors assessed before engagement. Signed DPAs in place. Annual security questionnaire reviews.

Security or compliance questions?

Our security team responds to all enquiries within 24 hours.

Email security@axiominfinity.net →