Trust centre

Controls you can inspect. Limits we state plainly.

Saxum is designed to preserve tenant boundaries, source identity, review decisions and release evidence. This page distinguishes implemented controls from live-deployment and customer proof that still requires external execution.

Implemented controls

Security and quality are part of the operating workflow

Tenant and process isolation

Forced PostgreSQL row-level policies, scoped transaction context and separate web, worker, webhook, maintenance and migration roles protect customer records and operational boundaries.

Encryption and identity

Record-bound encrypted secrets and artifacts, secure cookie sessions, scoped expiring service tokens, MFA replay protection and enterprise identity foundations reduce credential and record-transfer risk.

Controlled release

Deterministic quality gates, stale-approval invalidation, two-person review where configured and signed release evidence prevent silent automation from becoming authorization.

Supply-chain evidence

Exact dependency inventory, a deterministic SBOM, digest-only container configuration and signing workflows are included. Final wheel hashes and published image attestations remain deployment gates.

Recovery posture

Backup, restoration and destructive-drill tooling refuse live source targets. Achieved RTO and RPO must still be measured against isolated off-host systems.

Product quality

Isolated functional and branch-coverage matrices, source and marketing audits, signed samples, migrations, smoke tests and multi-width browser checks form the local release evidence.

Control boundary

What automation cannot do

AI suggestions cannot waive findings, approve releases, alter source facts, promote rule packs or authorize provider writes. Manual runs force fresh controls, and changed bound inputs invalidate cached results.

Customer-held authority

Saxum prepares, reconciles and evidences controlled outputs. The customer retains final credentials, regulated attestations and official-platform submission authority unless a separately authorized provider workflow has passed acceptance.

External qualification gates

Real systems and customers complete the evidence

Source-only tests cannot substitute for these executions.

Hosted infrastructure

Hosted PostgreSQL 17 and PostgreSQL 18 cross-role qualification, retained proof for the deployed major, final digest-pinned image build, vulnerability scan, publication, signature and provenance attestation.

Live providers and recovery

Real OIDC, Google, Microsoft and provider credentials, authorized write-back acceptance, revocation testing and off-host destructive recovery with measured RTO/RPO.

Commercial proof

Supervised paid pilots, external acceptance, measured intervention time, false-positive rate, straight-through processing and renewal evidence.