Skip to content
AxeroGo

Security

Security that starts with your own identity provider

Axero Go signs people in through the systems you already run, keeps access tied to your directory, and comes from the team that has secured enterprise intranets since 2008.

  • Hosted on Microsoft Azure
  • Encrypted at rest & in transit
  • Your own database & app instance
  • 35-day geo-redundant backups
  • Zone-redundant high availability
  • SSO via SAML, OpenID Connect & SCIM

Single sign-on

Sign in through your identity provider

People reach Axero Go through your own single sign-on. Multi-factor, conditional access, and the sign-in policies you already enforce stay with your identity provider, exactly where your IT team manages them. The handoff is signed, short-lived, and never puts a login token in a URL or a log.

Connected most often

Microsoft Entra ID SAML · OIDC · SCIM
Okta SAML · OIDC · SCIM
Google Workspace SAML · OIDC · Directory
Auth0 Auth0 Single sign-on
OneLogin SAML · SCIM
Duo Duo Single sign-on
JumpCloud JumpCloud SAML · SCIM
Workday HR directory
BambooHR HR directory
Rippling Rippling SAML · SCIM
ADP ADP OpenID Connect
Gusto Gusto HR directory

Plus all of these, out of the box

  • SAML
  • OpenID Connect
  • SCIM
  • SFTP
  • Access People HR
  • Apple
  • AWS Cognito
  • Breathe HR
  • Bubble
  • CAS
  • Cezanne HR
  • ClassLink
  • Clever
  • Cloudflare
  • CyberArk
  • Firebase
  • Fourth
  • GitHub
  • GitLab
  • Intuit
  • Keycloak
  • LastPass
  • LinkedIn
  • Login.gov
  • Microsoft AD FS · OAuth
  • miniOrange
  • NetIQ
  • NextAuth.js
  • Oracle
  • Ping Identity
  • SailPoint
  • Salesforce
  • Segment
  • Shibboleth
  • SimpleSAMLphp
  • Slack
  • Stripe
  • Supabase
  • Vercel
  • VMware
  • Xero

How your data is protected

The safeguards behind every Axero Go site

Access follows your directory

Connect your directory or HRIS and Axero Go creates each account as the person joins and closes it when they leave, within minutes of the change at your end. Access is granted and revoked where you already manage it, so nobody keeps a login they should not have.

Permissions and private spaces

Roles decide what each person can see and do. Sensitive work lives in private spaces that only their members can open, so a team's documents, discussions, and files stay with that team.

Encrypted end to end

Every connection runs over HTTPS with modern TLS, and the databases and files behind it are encrypted on disk.

Sign-in protection

Passwords are stored with strong one-way hashing, never in the clear. Reset links are single-use and expire within the hour, and sign-in endpoints are rate-limited against brute-force and credential-stuffing attempts.

Your data is yours

Every customer runs in their own dedicated database and application instance, so your content is never pooled with anyone else's. We don't sell it or mine it to train anything, and you can export it whenever you need to.

Built to stay up

Axero Go runs on Microsoft Azure with zone-redundant failover, so a single data-center fault doesn't take your intranet down. Your data is backed up continuously, with 35 days of geo-redundant history.

Built by Axero

Nearly two decades of enterprise intranets behind it

Axero Go comes from Axero, which has built intranets for large organizations since 2008. Axero is SOC 2 Type II compliant, and its cloud hosting environments are SSAE 16 (SOC 1, SOC 2 Type II) and ISO 27001 compliant. Axero Go itself is hosted on Microsoft Azure.

For Axero's full security and compliance detail, see axerosolutions.com/platform/technology-security.

Talk to us

For IT and security teams

Running a formal security review? We'll walk your team through how Axero Go handles identity, access, and your data.