Trust and Security Centre
The questions security, privacy and procurement teams ask about Axcess1, answered in one place.
Where your information is kept
- You choose where Axcess1 runs: on your own servers, in your own cloud tenant, or hosted and managed by SoftSim. It is the same software in each case.
- On your own servers, no information leaves your network.
- The service hosted by SoftSim runs in Canada. Backups, logs, search indexes and audit trails stay in the same region as the live data.
- Moving from one option to another later is a migration, not a new purchase.
Who owns the information
- Your organization owns its requests and records at all times. SoftSim acts only on your instructions.
- On request we provide a full export. At the end of a contract we return the records and then destroy all copies, backups and indexes.
- We never sell, share or mine your information.
Separation between organizations
- Each organization’s records are kept separate from every other organization’s, and every screen and every query is limited to the signed-in user’s own organization.
- A dedicated environment, with its own database and its own storage, is available for organizations that require one.
Encryption
- Information is encrypted in transit (HTTPS/TLS) and at rest (AES-256). SQL Server Transparent Data Encryption and storage-level encryption are supported.
- Where the platform allows it, the encryption keys can be managed by your organization.
Sign-in and access
- Every user signs in. Axcess1 connects to your Active Directory or LDAP directory or to SAML single sign-on, so your existing rules apply, including multi-factor authentication where your identity provider enforces it.
- Permissions follow the user’s role and are enforced on the server, not only hidden on the screen.
Audit trail
- Every change to a record is logged: who made it, when, and the values before and after. Failed sign-ins and AI suggestions are logged as well.
- Your administrators can export the logs.
Artificial intelligence
- Axcess1 does not need AI to work. AI is switched off until your administrator turns it on, one capability at a time, and it can be switched off again at any time.
- You choose the AI service: one managed by SoftSim, your own (you supply its address and key), or none.
- AI assists and never decides. It proposes; an authorized official approves or rejects every suggestion.
- We never train a model on your information, and nothing is sent to an outside AI service without your explicit approval.
Retention and holds
- Retention and disposition are configurable. Records under an access request, a complaint or a legal hold are never purged.
Incidents
- We notify your organization immediately of any suspected privacy or security incident, preserve the evidence and cooperate with your own breach plan.
SoftSim’s security credentials
- SoftSim is registered in the Government of Canada’s Contract Security Program. It holds a Top Secret Facility Security Clearance and a Document Safeguarding Capability up to Protected B, issued by Public Services and Procurement Canada.
- These credentials certify how SoftSim handles protected information as an organization. They are not a blanket approval of a service: each deployment is assessed and authorized by the customer’s own security authority, and we provide the evidence for that assessment.
Evidence for your security assessment
- On request we provide architecture diagrams, a shared-responsibility matrix, a control matrix, the system details your privacy team needs for its privacy impact assessment, and our answers to your security questionnaire.
- We say plainly what is independently certified and what is aligned by design.
Need the detail for your assessment?
Write to atip@softsim.ca for the security package, or send us your questionnaire. See also our privacy policy.