Built to be trusted with critical operations.
Towers, plants, fleets and cold chains depend on AXITEQ. Security is designed into every layer, from the device to the people who run it.
Security in every layer.
Encryption everywhere
TLS for data in transit between devices, gateways, platform and users. Encryption at rest for stored data and backups.
Least-privilege access
Role-based access control, single sign-on and multi-factor authentication, with every action written to an audit log.
Secure devices
Signed firmware, secure boot where hardware supports it, encrypted over-the-air updates and unique credentials per device.
24/7 monitoring
Our NOC watches platform health and security events around the clock, with documented incident response.
Data residency choices
Host in a cloud region of your choice, including in-Kingdom options for KSA customers, or on your own premises.
Resilience and backup
Redundant infrastructure, regular backups and tested recovery procedures, so operations keep running.
Five layers. One posture.
Controls at every point a threat could enter.
- Unique device identity and keys
- Signed and encrypted firmware updates
- Tamper and door sensors on critical sites
- Private APN and VPN tunnels
- SIM/eSIM lifecycle control and lock to device
- Network anomaly alerts
- Tenant isolation in multi-tenant deployments
- RBAC, SSO (SAML/OIDC) and MFA
- Audit logs of user and API activity
- 24/7 NOC with runbooks
- Change management and controlled releases
- Vulnerability scanning and patching
- Background checks where the law allows
- Security awareness training
- Confidentiality agreements for all staff
Frameworks that shape our controls.
We design our platforms and processes with these regulations and standards in mind, and help customers meet their own obligations.
Personal Data Protection Law of the Kingdom of Saudi Arabia, enforced by SDAIA.
Essential Cybersecurity Controls from Saudi Arabia's National Cybersecurity Authority.
International standard for information security management systems.
Security for industrial automation and control systems.
Trust criteria for security, availability and confidentiality of service providers.
Secure development practices for web applications and APIs.
Listing a framework does not mean AXITEQ holds a certification against it. Ask us for our current certification status, security pack and data processing agreement.
Found a vulnerability? Tell us.
We welcome reports from security researchers and will work with you to fix genuine issues quickly.
- Email the details to info@axiteq.com with the subject "Security report"
- Include steps to reproduce, affected URLs or devices, and impact
- Give us reasonable time to fix the issue before sharing it publicly
- Do not access, change or delete data that is not yours, or disrupt services
Where is my data hosted?
In the cloud region agreed in your contract, or on your premises. KSA customers can choose in-Kingdom hosting.
Who at AXITEQ can see my data?
Only staff who need it to deliver your service, such as NOC engineers, with access logged and reviewed.
Can we run a security review or penetration test?
Yes. We support customer security reviews and agreed testing, and share our security pack under NDA.
Do you sign a data processing agreement?
Yes. We sign a DPA with customers whose personal data we process.
How do you handle incidents?
Our documented incident response process covers detection, containment, customer notification and lessons learned.
Need our security documentation?
We share our security pack, architecture and policies under NDA with teams evaluating AXITEQ.