Legal & Data Handling

Privacy Policy

Effective: March 9, 2026 · Controller: AXUM SEC · Contact: security@axumsec.com

What We Collect

Tenant identifiers, API key metadata, file metadata (name, size, MIME type), and operational audit logs. We do not access or inspect unencrypted file contents beyond automated security scanning.

How We Use Information

To provide the file storage and sharing service, enforce security policies, run malware scans, generate audit trails, and improve platform reliability. Usage data is never sold or shared with third parties.

Confidential File Protection

Files uploaded in confidential mode are encrypted with AES-256-GCM before storage. Encryption keys are tenant-scoped. AXUM SEC cannot decrypt customer files without the tenant-specific key material.

Security Engines

Files are scanned by ClamAV and VirusTotal at upload time. Scan results and file hashes are logged. Quarantined files are isolated from both public and encrypted storage paths.

Data Retention

Customers control file lifecycle through the API. Deleted files are soft-deleted and recoverable. Audit logs are retained per tenant configuration. Contact security@axumsec.com for data removal requests.