Effective: March 9, 2026 · Controller: AXUM SEC · Contact: security@axumsec.com
Tenant identifiers, API key metadata, file metadata (name, size, MIME type), and operational audit logs. We do not access or inspect unencrypted file contents beyond automated security scanning.
To provide the file storage and sharing service, enforce security policies, run malware scans, generate audit trails, and improve platform reliability. Usage data is never sold or shared with third parties.
Files uploaded in confidential mode are encrypted with AES-256-GCM before storage. Encryption keys are tenant-scoped. AXUM SEC cannot decrypt customer files without the tenant-specific key material.
Files are scanned by ClamAV and VirusTotal at upload time. Scan results and file hashes are logged. Quarantined files are isolated from both public and encrypted storage paths.
Customers control file lifecycle through the API. Deleted files are soft-deleted and recoverable. Audit logs are retained per tenant configuration. Contact security@axumsec.com for data removal requests.