Security

Oxiom takes a defense-in-depth approach to protecting invoice, financial, and operational data for enterprise customers.

Infrastructure Security

Oxiom runs on enterprise cloud infrastructure with layered network protections, secure environment management, hardened deployment practices, and continuous monitoring designed to support availability and resilience for finance operations.

Data Security

Invoice and account data is protected with encryption at rest using AES-256-aligned controls and encryption in transit with TLS 1.3. Sensitive records are stored in access-controlled systems with logging and retention safeguards.

Access Control

Oxiom supports role-based access control, least-privilege administration, multi-factor authentication readiness, and enterprise identity controls to help customers manage who can see, approve, or export invoice data.

Compliance Program

Our security program is designed to support enterprise due diligence, including a roadmap toward SOC 2 Type II readiness and alignment with ISO 27001 control domains appropriate to the platform and customer environment.

Incident Response

Oxiom maintains documented incident-response procedures for identifying, triaging, containing, investigating, communicating, and remediating security events that may affect the platform or customer data.

Penetration Testing

We assess the platform through vulnerability management practices, security reviews, and periodic testing to identify and address weaknesses before they become material risks to customers.

Responsible Disclosure

Security researchers and customers can report suspected issues to security@oxiom.ai. We review credible reports promptly and coordinate remediation based on severity and operational impact.