Axentra

Security and Trust

How Axentra protects client information

Information security is addressed through employment and vendor obligations, internal policies, workforce training, approved IT assets, system-access controls and requirements agreed for the engagement.

Quality and security responsibilities are considered together during delivery setup. Team members receive access only to the information and systems required for their assigned roles.

Employment and Vendor Obligations

Responsibilities apply to the people and providers involved

Personnel and relevant vendors receive confidentiality, security and data-handling responsibilities before they receive access needed for the work.

Employment obligations

  • Confidentiality and data-protection obligations
  • Intellectual-property and information-security obligations
  • Acceptable-use and AI-use rules
  • Training and policy acknowledgement
  • Continuing confidentiality after employment ends
  • Client-specific instructions

Vendor obligations

  • Confidentiality and data protection
  • Information security and access restrictions
  • AI use and incident reporting
  • Return or deletion of information
  • Restrictions on further subcontracting
Policies and training

Clear instructions for handling client information

Personnel acknowledge relevant policies, complete workforce training and receive any engagement-specific instructions before delivery begins.

  • Information security
  • Confidentiality and data handling
  • Privacy
  • Acceptable IT use
  • Remote working
  • Password and access management
  • AI use
  • Incident reporting
  • Retention and deletion
  • Vendor access
IT assets and access

Access is limited to the work assigned

Devices, user accounts, permitted software and remote-working arrangements are set for the engagement. Access is changed or removed when a role or assignment ends.

Before access

Confirm the device, user role, permitted systems and client restrictions.

During delivery

Use the assigned access and follow the engagement's download, storage, software and remote-working rules.

When access changes

Remove or update access, return assets and complete the required information-return or deletion steps.

Information handled

Safeguards reflect the information involved

Axentra identifies the types of information involved and follows the client, legal and contract terms that apply to their handling.

  • Confidential information
  • Personal data
  • Sensitive personal data
  • Protected health information
  • Intellectual property
  • Commercially sensitive information
  • Privileged material
  • Restricted records
  • Client instructions and contract restrictions
  • Tools permitted for the engagement
  • Access controls and minimum necessary data
  • Human review
  • Vendor obligations
  • Escalation procedures
AI Use

Use is limited by client instructions and engagement terms

Client information is not entered into unauthorised public AI tools or used by Axentra for independent model training.

Incident Response

Report, contain and respond

Personnel report suspected incidents through an internal escalation route. According to the engagement terms, response covers containment, access changes, record preservation, client notification, corrective action and recovery as applicable.

Business Continuity

Plan for interruptions

Staffing, access, communication and recovery arrangements are considered during setup. Continuity steps are aligned with the work and the client's priorities.

PHI AND HIPAA-RELATED ENGAGEMENTS

Confirm roles before processing

Where work involves protected health information, the parties address permitted use, safeguards, access, incident duties and any Business Associate Agreement before processing begins. Axentra does not describe itself as HIPAA certified.

CERTIFICATION POSITION

Claims reflect the current position

Axentra does not claim an information-security or privacy certification it has not obtained. Relevant policies, practices and available documentation can be discussed during client diligence.

Client diligence

Discuss security and data-handling requirements

Clients can review the information involved, access arrangements, contract terms and available documents before the engagement begins.