VOL.01The Trust Issue

Your clients' data,
kept separate and kept safe.

Agencies run their clients' brands through Axiom GEO. That only works if isolation, access and integrations are handled properly. Here's how we do it.

How we handle data

Tenant isolation by default

Every workspace is isolated at the database level. One client's prompts, analytics, OAuth tokens and reports are never visible to another — there is no shared pool to leak from.

Encryption in transit and at rest

All traffic is served over TLS. Data and backups sit on encrypted storage, and off-site backups are age-encrypted with keys held separately from the server.

Scoped, revocable integrations

Google Analytics and Search Console connect via OAuth per workspace, with read-only scopes. Disconnect at any time from the workspace and the tokens are revoked immediately.

Least-privilege access

Operator and admin tooling is gated to super-admin accounts and never exposed to client viewers. Client logins see only their own workspace.

Transparent sub-processors

The AI engines and Google APIs we call are named sub-processors. They receive only the prompt and domain needed to run a check — never one client's data mixed with another's.

Auditable actions

Every credit-consuming action is logged by type, so there is a clean trail of what ran, when and against which workspace — useful for your own client reporting and reconciliation.

Questions about data handling?

We're happy to walk an agency or a client's security team through isolation, sub-processors and backups. Reach us via the contact form and a human replies.