Skip to main content
AXELHENRY
Security & compliance

Security built into the platform, not bolted on

Every Axel Henry tenant benefits from role-based access control, configurable permissions, single sign-on and full audit logging as standard.

Role-Based Access Control

Nine system-defined roles out of the box, plus unlimited custom roles built from a granular, database-backed permission catalogue spanning every module.

Configurable Permissions

Every permission carries a visibility scope — self, team, business unit, or company-wide — so access always matches organisational structure, not a fixed template.

Multi-Factor Authentication

MFA can be enabled per user and enforced centrally by administrators from the Admin Control Centre.

Single Sign-On

Sign in with your existing corporate identity provider instead of managing another password.

Microsoft Entra ID Integration

Native SSO integration with Microsoft Entra ID (Azure AD), alongside Google Workspace SSO.

Audit Logging

Every sensitive action — approvals, permission changes, promotion decisions and more — is written to a company-scoped audit log.

Account Protection

Automatic account lockout after repeated failed sign-in attempts, with configurable password and session policy.

GDPR-Aware Data Handling

Candidate records include explicit GDPR consent tracking, and employee data visibility is always scoped by role and permission.

Encryption

Passwords are hashed with industry-standard bcrypt; data is encrypted in transit via HTTPS/TLS end-to-end.

Secure, Tenant-Isolated Architecture

Every tenant's data is isolated at the query layer by company, so no customer can ever see another customer's data.

Data Retention & Lifecycle

Structured leaver/offboarding processes ensure employee records are handled consistently when someone leaves the organisation.

Backup & Recovery

Hosted on managed, redundant cloud infrastructure with automated database backups.

Architecture

Tenant-isolated by design

Every customer's data is isolated at the query layer by company — no customer can ever access another customer's records, and every request is scoped to your organisation.

One secure, isolated tenant per organisation

Have a security questionnaire to complete?

Our team can walk your security or compliance team through our architecture directly.