Axine Labs
Legal

Data Security Architecture

Enterprise encryption standards, air-gapped container boundaries, and data integrity protocols.

Effective: 12 July 2026
Last updated (UTC):2026-08-20T00:00:00Z
Legal pages are localised, and the English version governs all interpretations.For legal disputes, the English statutory wording holds primary jurisdiction under the laws of England and Wales.

1. Cryptographic Encryption Standards

All data entering and leaving Axine Labs infrastructure is protected using modern cryptographic ciphers:

Storage volumes housing intermediate reflectance cubes and processed mineral layers are encrypted at rest using dedicated hardware security modules (HSMs).

  • Encryption in Transit: Enforced TLS 1.3 with Perfect Forward Secrecy (ECDHE-RSA/ECDHE-ECDSA) and strict HSTS headers.
  • Encryption at Rest: AES-256-GCM encryption on all database volumes, Parquet stores, and GeoTIFF object buckets.
  • Cryptographic Hash Sealing: SHA-256 validation seals attached to all processed outputs to ensure tamper-evident delivery.

2. Lisaris Air-Gapped Security Architecture

For defense organizations and sovereign exploration entities operating under classified or air-gapped restrictions, Axine Labs provides the Lisaris analyst assistant as a containerized, self-hosted deployment.

Lisaris executes entire spectral queries, pricing estimations, and archive lookups locally on Customer infrastructure without transmitting geospatial coordinates or proprietary project boundaries to external networks.

3. Ephemeral Processing & Zero-Retention Mode

Customers handling sensitive exploration targets may enable 'Zero-Retention Mode' for commercial tasking and custom processing runs.

In Zero-Retention Mode, intermediate reflectance rasters are held exclusively in volatile memory (RAM) during spectral unmixing and permanently expunged immediately following deliverable handoff.

CONFIDENTIAL EXPLORATION GUARANTEE: In Zero-Retention Mode, no copy of Customer coordinates, intermediate reflectance rasters, or interpreted mineral layers is retained on Axine servers once the download link expires.

4. Infrastructure Access & Role-Based Controls (RBAC)

Internal access to production infrastructure is governed by strict principle-of-least-privilege policies:

  • Multi-Factor Authentication: Hardware security key (FIDO2 / WebAuthn) enforced across all infrastructure access points.
  • Ephemeral Bastion Access: Short-lived, auditable SSH/IAM certificates with automated session termination.
  • Continuous Audit Logging: Immutable audit trails recording every administrative action and pipeline execution.

5. Vulnerability Management & Incident Response

Our security engineering team conducts continuous automated vulnerability scans, static code analysis, and routine third-party penetration tests.

In the event of a confirmed security incident affecting customer data, Axine Labs commits to notifying affected customers and competent regulatory authorities within 72 hours of confirmation.

Axine Labs, 30 N Gould St Ste 100, Sheridan, WY 82801 · contact@axinelabs.com