Skip to content

[ Security ]

For the most sensitive records in community care.

A client file at a recovery home carries medical, legal, and family history in one place. Axon Health holds it in an isolated workspace, scopes who can see it by role and house, and records every change, including everything the AI touches.

[ Security at a glance ]

Full detail in the sections below

Workspace

Database per organization

Access

Roles + house scoping

Sign-in

2FA, passkey & biometric

Data protection

Encrypted in transit & at rest

Audit

Field-level change log

AI governance

No model training

Retention

20-year legal hold

Compliance

HIPAA & PHIPA certified

Controls

SOC 2 Type II certified

Procurement

Security documentation

Interoperability

HL7 FHIR ready: exchange records with EHRs and health systems

[ Protection by default ]

Security across every layer of client care.

One database per organization

Your records live in their own logical database, never pooled with another organization's. A problem in one workspace cannot expose another's data.

Encryption everywhere

Data is encrypted in transit and at rest: records, documents, chat, and AI outputs alike.

Scoped by role and house

Staff see only clients in houses assigned to them. A men's-home manager never sees a women's-home file, and per-client conflict-of-interest blocks go narrower still.

Custom roles to the menu item

Overnight staff who see only logs. Kitchen staff who see only documents. Admins build roles with menu-item-level permissions, with no vendor ticket required.

Permanent by design

Medication corrections void and restate, so the original entry is preserved. Shared client journals can't be silently deleted. The record is built for courts and audits.

Activity logging

A system-wide, field-level audit log records who changed what and when, across every module, alongside each client's own journey history.

[ Access and permissions ]

The right staff see the right clients.

Axon separates organizational hierarchy, house assignment, and per-record visibility, so a whole team can work in one system without widening who sees what.

Hierarchy without seat limits

Admin, Manager, and Coordinator tiers plus fully custom roles, so a whole team works in one system without widening who sees what.

  • Admin, Manager, and Coordinator tiers, plus fully custom roles per menu item
  • Unlimited staff seats: volunteers and overnight staff included, scoped down
  • Permission changes land in the audit trail

Per-record visibility

Beyond role and house, individual records carry their own audience, set by the person who created them.

  • Every shift log carries a mandatory audience: creator, all staff, or named staff
  • Clients control whether staff see their private sobriety tracking
  • Medication access is granted explicitly, never part of the default set

Human review before anything leaves

Reports move draft to review to finalized with inline comments. Nothing reaches a court or funder without a person signing off, and the disclosure travels with it.

  • Every AI-assisted report carries a disclosure note for its recipients
  • The reviewer, the sign-off, and the timing stay attached to the report
  • Finalized versions stay reconstructable from the audit trail

Permanent by design

Corrections void and restate rather than overwrite. The original entry stays in the record, which is what makes it usable in a court or an audit.

  • Medication corrections preserve the original entry alongside the restatement
  • Shared client journals cannot be silently deleted
  • Records are held for the 20-year legal retention period

[ AI governance ]

The bar AI should meet before it touches a client file.

Care records need a higher bar than generic chat. Axon treats every AI query, draft, and output as a governed surface.

01

No model training

Client records, queries, and documents are never used to train the underlying models, and are not retained by them.

02

Grounded in your database

The assistant answers from your organization's records, never the open web. Missing data is flagged, not fabricated.

03

Answers, not advice

The AI filters, retrieves, and drafts. It does not make clinical suggestions or medication recommendations, by explicit design.

04

Human review, always

Reports move draft → review → finalized, with inline comments. Nothing reaches a court or funder without a person signing off.

05

Disclosed on every report

Every AI-assisted report carries a disclosure note for its recipients, so courts, boards, and funders know how it was produced.

06

Prompt-injection defenses

Uploaded documents and user text are treated as data, never as instructions, with strictly structured outputs on every call.

[ Security review ]

Built for ministry, board, and procurement review.

Security documentation

Architecture, data handling, subprocessors, and controls, ready for vendor diligence.

DPA and privacy review

Clear contractual handling for client data: retention, deletion, and privacy commitments.

SOC 2 Type II certified

Access, change management, logging, and monitoring controls independently audited, with third-party HIPAA certification.

Enterprise access

Two-factor authentication today; passkey and biometric sign-in on mobile; admin-owned access reviews.

[ FAQ ]

Security questions teams ask first.

A practical starting point for executive directors, boards, and IT reviewers evaluating Axon Health.

DPAAudit logsNo model trainingHouse scoping
Do you train AI models on our data?

No. Client records, queries, and documents are processed only to answer your request and are never used to train the underlying models.

Can every staff member see every client?

No. Visibility is scoped by role and house assignment, medication access is granted explicitly, and admins can block a specific staff member from a specific client entirely.

Where is our data processed?

Axon Health runs on AWS, with each organization's records in their own logical database. Deployment specifics and data-residency requirements are reviewed during security discovery.

Can we export audit history?

Yes. The system-wide change log, per-client journey history, and section-by-section PDF exports support legal requests, incident review, and funder audits.

How long are records kept?

Deleted records follow a soft-delete convention with retention windows up to 20 years, matching child-welfare and legal record-keeping requirements.

How do you handle security reviews?

We support technical and procurement reviews with documentation on architecture, controls, privacy, and data handling. Bring your compliance team to the first call.

Bring security into the first conversation.

Talk with us about your access model, ministry requirements, AI policies, and review path.

  • Unlimited staff seats
  • HIPAA & SOC 2 aligned
  • Multi-site & multi-program