Security and Trust
How Axentra protects client information
Information security is addressed through employment and vendor obligations, internal policies, workforce training, approved IT assets, system-access controls and requirements agreed for the engagement.
Quality and security responsibilities are considered together during delivery setup. Team members receive access only to the information and systems required for their assigned roles.
Responsibilities apply to the people and providers involved
Personnel and relevant vendors receive confidentiality, security and data-handling responsibilities before they receive access needed for the work.
Employment obligations
- Confidentiality and data-protection obligations
- Intellectual-property and information-security obligations
- Acceptable-use and AI-use rules
- Training and policy acknowledgement
- Continuing confidentiality after employment ends
- Client-specific instructions
Vendor obligations
- Confidentiality and data protection
- Information security and access restrictions
- AI use and incident reporting
- Return or deletion of information
- Restrictions on further subcontracting
Clear instructions for handling client information
Personnel acknowledge relevant policies, complete workforce training and receive any engagement-specific instructions before delivery begins.
- Information security
- Confidentiality and data handling
- Privacy
- Acceptable IT use
- Remote working
- Password and access management
- AI use
- Incident reporting
- Retention and deletion
- Vendor access
Access is limited to the work assigned
Devices, user accounts, permitted software and remote-working arrangements are set for the engagement. Access is changed or removed when a role or assignment ends.
Before access
Confirm the device, user role, permitted systems and client restrictions.
During delivery
Use the assigned access and follow the engagement's download, storage, software and remote-working rules.
When access changes
Remove or update access, return assets and complete the required information-return or deletion steps.
Safeguards reflect the information involved
Axentra identifies the types of information involved and follows the client, legal and contract terms that apply to their handling.
- Confidential information
- Personal data
- Sensitive personal data
- Protected health information
- Intellectual property
- Commercially sensitive information
- Privileged material
- Restricted records
- Client instructions and contract restrictions
- Tools permitted for the engagement
- Access controls and minimum necessary data
- Human review
- Vendor obligations
- Escalation procedures
Use is limited by client instructions and engagement terms
Client information is not entered into unauthorised public AI tools or used by Axentra for independent model training.
Report, contain and respond
Personnel report suspected incidents through an internal escalation route. According to the engagement terms, response covers containment, access changes, record preservation, client notification, corrective action and recovery as applicable.
Plan for interruptions
Staffing, access, communication and recovery arrangements are considered during setup. Continuity steps are aligned with the work and the client's priorities.
Confirm roles before processing
Where work involves protected health information, the parties address permitted use, safeguards, access, incident duties and any Business Associate Agreement before processing begins. Axentra does not describe itself as HIPAA certified.
Claims reflect the current position
Axentra does not claim an information-security or privacy certification it has not obtained. Relevant policies, practices and available documentation can be discussed during client diligence.
Discuss security and data-handling requirements
Clients can review the information involved, access arrangements, contract terms and available documents before the engagement begins.