Security
Oxiom takes a defense-in-depth approach to protecting invoice, financial, and operational data for enterprise customers.
Infrastructure Security
Oxiom runs on enterprise cloud infrastructure with layered network protections, secure environment management, hardened deployment practices, and continuous monitoring designed to support availability and resilience for finance operations.
Data Security
Invoice and account data is protected with encryption at rest using AES-256-aligned controls and encryption in transit with TLS 1.3. Sensitive records are stored in access-controlled systems with logging and retention safeguards.
Access Control
Oxiom supports role-based access control, least-privilege administration, multi-factor authentication readiness, and enterprise identity controls to help customers manage who can see, approve, or export invoice data.
Compliance Program
Our security program is designed to support enterprise due diligence, including a roadmap toward SOC 2 Type II readiness and alignment with ISO 27001 control domains appropriate to the platform and customer environment.
Incident Response
Oxiom maintains documented incident-response procedures for identifying, triaging, containing, investigating, communicating, and remediating security events that may affect the platform or customer data.
Penetration Testing
We assess the platform through vulnerability management practices, security reviews, and periodic testing to identify and address weaknesses before they become material risks to customers.
Responsible Disclosure
Security researchers and customers can report suspected issues to security@oxiom.ai. We review credible reports promptly and coordinate remediation based on severity and operational impact.