Customer-selected folder boundary
Only folders and connected sources selected by the customer participate in the evidence layer.
SECURITY AND CUSTOMER CONTROL
Axiomyx security controls apply to official, unmodified Private Edition distributions deployed in customer-controlled infrastructure.
PUBLICLY SUPPORTABLE CONTROLS
Only folders and connected sources selected by the customer participate in the evidence layer.
Standard Private Edition does not require an Axiomyx-hosted operational data plane.
Official customer archives and release manifests have published SHA-256 identities so supported builds can be verified.
The runtime verifies KMS-signed entitlements without shipping the signing private key in customer packages.
Staging and production KMS duties remain separated; private signing material is not distributed.
Licence keys are not persisted by the runtime, and the activation service applies request, timeout and rate boundaries.
Personal uses the private boundary of the installed desktop product. Business adds customer-controlled OIDC and authorised-user admission.
Deployments expect protected PostgreSQL transport plus safe backup, restore and data-preserving uninstall paths.
Support uses synthetic or minimised reproductions and customer-reviewed sanitised diagnostics.
HOST-ADMINISTRATOR THREAT BOUNDARY
A customer administrator or root user can technically replace the runtime, public-key registry, database, local clock or complete installation state. Axiomyx does not claim local licensing is tamper-proof against deliberate administrator modification.
Deliberate modification or circumvention is unsupported and remains subject to the software licence. Normal Private Edition operation does not require permanent online validation, hardware attestation or appliance-style DRM. Compensating controls include hash-verified customer packages and manifests, KMS-signed local entitlements, support limited to verified official builds, provider activation limits, monitoring where available and contractual restrictions.