Machine-locked licensing · Remote kill-switch · Air-gapped ready — OT SIEM/SOAR in pipeline.

Free trial

Axix Hawk

Security

Security is not a feature. It is the foundation.

Cryptographic licensing, hardened runtimes, runtime detection, and tenant isolation — designed for hostile client environments.

Five layers of enforcement

Each layer independent; all required.

L5

Real-time heartbeat & revoke

Products phone home. Revoke once — every instance stops within one heartbeat cycle. Grace period for offline clients.

L4

Distroless Docker + seccomp

No shell, no package manager, syscall whitelist. Images signed with cosign; unsigned containers refuse to start.

L3

JWT / Keycloak auth

SSO for end users. Tokens bound to machineId — valid JWT on the wrong hardware is rejected.

L2

RSA-signed license file

Signed blobs with org, product, tier, features, expiry. Embedded public key — no server needed to verify offline.

L1

Hardware fingerprint lock

SHA-256 of stable host signals. Licenses cannot be copied to another machine without re-issuance.

Cryptography

RSA-2048

License blobs signed so clients verify offline with an embedded public key.

AES-256-GCM

Key material encrypted at rest in the Hawk control plane.

HMAC webhooks

Lifecycle deliveries signed so receivers can reject forged events.

SHA-256 fingerprints

Stable host signals hashed into machine_id for binding.

RUNTIME HARDENING

Distroless, seccomp, cosign, Falco

No shell to strip licensing. Unsigned images refuse to start. Runtime rules catch shell-in-container, ptrace, and license exfiltration.

  • Distroless base images
  • Seccomp syscall whitelist
  • Cosign signature enforcement
  • Falco alert → audit correlation
Runtime hardening stack

Multi-tenant isolation

Keycloak realms

SSO boundaries per vendor tenant — roles on every API route.

Postgres RLS

Row-level security — zero cross-tenant leakage by design.

machineId-bound JWT

Valid tokens on the wrong hardware are rejected.

AUDIT

Append-only, hash-friendly trails

Every generate, revoke, deploy, heartbeat anomaly, and Falco alert lands in an append-only log — SOC 2-ready evidence for reviews.

Audit log view

Compliance readiness

Honest scope — not rubber-stamp claims.

SOC 2-ready

Audit trails and access controls designed for readiness programs.

GDPR-minded heartbeats

license_id, machine_id, versions — no PII by design.

IEC 62443 alignment

Via OT SIEM/SOAR pipeline — labeled clearly as roadmap.

What's live vs pipeline

Core licensing + Falco today. OT SIEM/SOAR in development.

CapabilityStatus
Licensing lifecycleLive
Agent + SDKsLive
Falco detectionLive
Audit + webhooksLive
OT SIEMPipeline
OT SOARPipeline
Advanced ICS protocol parsersPipeline
Full OT playbook libraryPipeline

Binding that survives copy attempts

Hardware fingerprints and signatures stop casual license sharing.

  • Stable host signal hashing
  • Signed license blobs
  • Re-issue workflow on hardware change
Binding that survives copy attempts visual

Hardened delivery layers

Reduce the attack surface of what you ship to customer sites.

  • Signed container images
  • Locked-down runtimes
  • Runtime anomaly signals
Hardened delivery layers visual

Audit trails for reviews

Show generate, revoke, and anomaly events when security asks.

  • Append-only event history
  • Export-friendly records
  • Correlated revoke workflows
Audit trails for reviews visual

Validate security controls in trial

Start free and prove bind failure and revoke timing to your reviewers.

  • PoC scripts your team can run
  • No credit card required
  • Enterprise path for air-gap
Validate security controls in trial visual

Security FAQ

Yes — license generate, revoke, deploy, and anomaly events land in an append-only trail suitable for security reviews.

Request a security architecture walkthrough

We will map layers to your threat model and deployment modes.