1. Cryptographic Encryption Standards
All data entering and leaving Axine Labs infrastructure is protected using modern cryptographic ciphers:
Storage volumes housing intermediate reflectance cubes and processed mineral layers are encrypted at rest using dedicated hardware security modules (HSMs).
- Encryption in Transit: Enforced TLS 1.3 with Perfect Forward Secrecy (ECDHE-RSA/ECDHE-ECDSA) and strict HSTS headers.
- Encryption at Rest: AES-256-GCM encryption on all database volumes, Parquet stores, and GeoTIFF object buckets.
- Cryptographic Hash Sealing: SHA-256 validation seals attached to all processed outputs to ensure tamper-evident delivery.
2. Lisaris Air-Gapped Security Architecture
For defense organizations and sovereign exploration entities operating under classified or air-gapped restrictions, Axine Labs provides the Lisaris analyst assistant as a containerized, self-hosted deployment.
Lisaris executes entire spectral queries, pricing estimations, and archive lookups locally on Customer infrastructure without transmitting geospatial coordinates or proprietary project boundaries to external networks.
3. Ephemeral Processing & Zero-Retention Mode
Customers handling sensitive exploration targets may enable 'Zero-Retention Mode' for commercial tasking and custom processing runs.
In Zero-Retention Mode, intermediate reflectance rasters are held exclusively in volatile memory (RAM) during spectral unmixing and permanently expunged immediately following deliverable handoff.
4. Infrastructure Access & Role-Based Controls (RBAC)
Internal access to production infrastructure is governed by strict principle-of-least-privilege policies:
- Multi-Factor Authentication: Hardware security key (FIDO2 / WebAuthn) enforced across all infrastructure access points.
- Ephemeral Bastion Access: Short-lived, auditable SSH/IAM certificates with automated session termination.
- Continuous Audit Logging: Immutable audit trails recording every administrative action and pipeline execution.
5. Vulnerability Management & Incident Response
Our security engineering team conducts continuous automated vulnerability scans, static code analysis, and routine third-party penetration tests.
In the event of a confirmed security incident affecting customer data, Axine Labs commits to notifying affected customers and competent regulatory authorities within 72 hours of confirmation.
