For your reviewers

What your security and finance reviewers will ask

If you're bringing Axemere to a CISO or a Finance reviewer before you activate it, this page is built to forward as-is. Every claim below links back to the same technical detail our own engineers work from, not a simplified version written just for this page.

We never see your prompts or responses

Axemere does not store, view, or log the content of prompts or responses, under any circumstances. What's retained is execution-record metadata (org/workload attribution, model, token counts, cost, policy decision, timestamps) plus a SHA-256 hash of the request and response for tamper-evident audit purposes. The raw text is never written to any database or log.

Credentials are encrypted, not just access-controlled

Provider API keys stored inline are protected with envelope encryption: a fresh key per credential, wrapped by a dedicated Cloud KMS key that never leaves KMS, on top of the database's own standard disk-level encryption at rest. Every gateway authenticates to the control plane over mTLS with a certificate whose private key never leaves the gateway it was generated on.

Every execution generates a signed, verifiable record

Execution records are hashed and submitted to an append-only ledger, periodically batched into a Merkle tree whose root is anchored to an external timestamp authority (RFC 3161). Your reviewer doesn't have to take engineering's word for what happened: they can verify a record hasn't been altered after the fact.

Compliance status, stated plainly

Axemere is working toward SOC 2 Type II certification. The Compliance package adds cryptographically signed, tamper-evident audit exports designed to support GDPR, HIPAA, and financial services regulatory requirements. We'll tell you exactly where certification stands if you ask, not imply it's further along than it is.

Your traffic doesn't have to leave your infrastructure

The self-hosted gateway runs entirely in your own environment; AI traffic never passes through Axemere. The Control Plane manages policy, credentials, and analytics for a self-hosted fleet the same way it does for the managed gateway, so centralized governance doesn't require centralizing your traffic.

Need the technical detail, not the summary?

The Security Overview docs cover every layer above in full: the exact cryptographic standards in use (Ed25519 policy signing, AES-256-GCM credential encryption, RFC 3161 timestamp anchoring), what each layer does and does not protect against, and how to independently verify a Merkle proof.

Read the Security Overview docs

Have a question this page doesn't answer?

Reach out directly and we'll get a straight answer to you or your reviewer, not a sales deck.