Security

Encryption, strong authentication, backups, protection against cyberattacks, data confidentiality. What we actually implement, presented to be verified — not merely stated.

Guiding principle

Secure by default, not by add-on.

A framework bolted on after the fact protects poorly. AXIS FINANCE's architecture — this website as much as the systems behind it — was designed from the outset on the principle of least privilege and a reduced attack surface.

This institutional website is a direct illustration: it collects no unnecessary data, runs no third-party code, and relies on a static architecture that eliminates entire classes of vulnerability by construction.

Protection framework

Five measures, verifiable rather than merely stated.

Data encryption

Systematic encryption of data in transit (HTTPS enforced, HSTS with preload) and of sensitive data at rest on internal systems. No information travels unencrypted between your device and our servers.

Multi-factor authentication

Access to internal systems and to KANU accounts is protected by two-factor authentication. No single password is ever enough to reach sensitive information or initiate a transaction.

Backups

Regular backups with tested restores, recovery time and data loss objectives defined by service type. Lost data remains a handled exception, never an accepted risk.

Protection against cyberattacks

Minimal attack-surface architecture, strict security headers (CSP, origin isolation), periodic penetration testing by an independent external provider, and a coordinated disclosure programme for security researchers.

Data confidentiality

No advertising cookies, no third-party analytics, no external resource loaded on this site. Strict segregation between advisory, brokerage and research activities to prevent any cross-use of information.

Coordinated disclosure

A documented programme, with published response times and a history of reports handled — so a security researcher knows exactly what to expect.

The full programme

Verifiable, not just stated

Check these points yourself.

None of these points asks you to take our word for it. Each can be verified in seconds, by anyone.

  • HTTPS and HSTS encryptionIn place
  • Security headers (CSP, origin isolation)In place
  • Zero third-party dependency on this siteIn place
  • Coordinated disclosure programme (RFC 9116)In place
  • Independent certification (SSL Labs, Security Headers)In progress

Test this site at securityheaders.com or ssllabs.com/ssltest — the results are public and don't depend on us.

A question about our security framework?

Security and compliance questionnaires are handled by our dedicated function.

Download KANU