Machine-locked licensing · Remote kill-switch · Air-gapped ready — OT SIEM/SOAR in pipeline.

Free trial

Axix Hawk

How it works

From SDK embed to licensed deployment

Three steps. No honor-system keys. Cryptographic binding from day one.

Three steps to first license

Most teams ship in under 15 minutes after console setup.

  1. 01

    Register & embed SDK

    Define your product in the Hawk console and embed our lightweight client libraries. Most teams ship in under 15 minutes.

  2. 02

    Deploy to client hardware

    Push a signed, distroless Docker image. Each license is cryptographically bound to the client machine fingerprint — not a reusable key.

  3. 03

    Control from one dashboard

    Renew, revoke, and monitor every deployment. Heartbeats every ~30 minutes; revoke takes effect within one cycle. Full audit trail.

ARCHITECTURE

Vendor console → Platform API → Agent → License blob → Customer machine

The control plane stays with you. The enforcement plane runs on customer hardware — online, hybrid, or air-gapped.

End-to-end Hawk flow

What happens on revoke

Remote kill-switch without a truck roll.

1

Mark revoked

Operator clicks revoke in the vendor console for the target license.

2

Next heartbeat

Agent phones home (~30 min). Revoke takes effect within one cycle.

3

Immediate path

Container restart exits immediately when the revoked state is loaded.

4

Audit

Append-only log records the revoke event for finance and security.

Operator touchpoints

Validate install health without fragile custom checkers.

Issue license

Bind a signed blob to the machine fingerprint from the vendor console.

Check agent health

Read local status from the agent — license state, machine ID, and grace window.

Revoke in console

Mark revoked once; enforcement lands on the next heartbeat or restart.

Who owns each plane

You (vendor)

Console, product definitions, signing keys, revoke policy, white-label UX.

Hawk platform

License issuance API, heartbeat intake, webhooks, multi-tenant isolation.

Customer machine

Agent, license blob, SDK gates, optional Falco runtime rules.

Why not build it yourself?

CapabilityAxix HawkBuild your own
RSA license signingIncluded2–4 weeks
On-prem agent + graceIncluded4–8 weeks
SDKsIncluded4–6 weeks / runtime
White-label consoleIncluded8–16 weeks
Falco + hardeningIncluded4–8 weeks
OT SIEM/SOARPipeline included6–12+ months
Time to first license~30 minutes6–12 months

Teams ship safer with Hawk

“We went from honor-system license keys to hardware-bound deployment in a week. Zero unauthorized installs since.”

Sarah ChenCTO, Vertex ISV

“The kill-switch saved us when a client stopped paying. Revoked at 2pm; their instance was down before end of day.”

Marcus OkonkwoHead of Delivery, Helix Integrators

“Distroless images plus cosign signing let us pass a security review we had failed twice before.”

Elena VasquezVP Engineering, Praxis Software

Define the product once

Model seats, tiers, and feature flags in the Hawk console before you ship binaries.

  • Product and tier configuration
  • Client org separation
  • Feature gates ready for embed
Define the product once visual

Deploy the agent beside your runtime

Local verification and heartbeats stay close to the workload.

  • Offline-capable verification
  • Heartbeat to the vendor console
  • Status checks during bring-up
Deploy the agent beside your runtime visual

Operate revoke and renew

Day-2 operations stay in one place — no emergency SSH hunt.

  • One-click revoke
  • Renew without reinstall
  • Webhook fan-out to ops tools
Operate revoke and renew visual

Walk the flow on a trial

Use a free trial to rehearse issue → bind → revoke before customers see it.

  • Sandbox client org
  • PoC checklist included
  • Upgrade when ready
Walk the flow on a trial visual

How it works FAQ

Most teams define a product, issue a license, and gate a feature within a working session.

Walk the architecture with us

30-minute demo — licensing, agent, revoke, and deployment security for your stack.