Security

Security information

Current product stage

CaseAxis is a private product in design-partner preparation. Public demonstrations use synthetic data. Real customer AML data remains prohibited until the applicable production security, privacy, identity, infrastructure, model-governance, backup/restore, and independent-assurance gates have been verified for the intended deployment.

Security design principles

Claims we do not make

CaseAxis does not claim SOC 2 certification, regulator approval, universal regulatory compliance, or production readiness unless and until the relevant independent evidence actually exists.

Report a security issue

Send suspected security issues to hello@getcaseaxis.com with “[Security]” in the subject line. Include a concise description, affected surface, reproduction steps using non-sensitive data, and any supporting evidence that can be shared safely.

Please do not include passwords, API keys, private keys, real customer AML/KYC/transaction data, or destructive exploit payloads in an initial report.

Responsible testing

Do not conduct destructive testing, social engineering, denial-of-service testing, or testing against data or systems you do not own or have explicit permission to assess. There is no public bug-bounty program at this stage.

Buyer security review

Prospective design partners can request a focused security/architecture discussion after initial discovery. Security documentation should be treated as evidence-specific: deployed controls, planned controls, and customer-required controls are distinguished rather than presented as interchangeable.