One database per organization
Your records live in their own logical database, never pooled with another organization's. A problem in one workspace cannot expose another's data.
[ Security ]
A client file at a recovery home carries medical, legal, and family history in one place. Axon Health holds it in an isolated workspace, scopes who can see it by role and house, and records every change, including everything the AI touches.
[ Security at a glance ]
Full detail in the sections below
Workspace
Database per organization
Access
Roles + house scoping
Sign-in
2FA, passkey & biometric
Data protection
Encrypted in transit & at rest
Audit
Field-level change log
AI governance
No model training
Retention
20-year legal hold
Compliance
HIPAA & PHIPA certified
Controls
SOC 2 Type II certified
Procurement
Security documentation
Interoperability
HL7 FHIR ready: exchange records with EHRs and health systems
[ Protection by default ]
Your records live in their own logical database, never pooled with another organization's. A problem in one workspace cannot expose another's data.
Data is encrypted in transit and at rest: records, documents, chat, and AI outputs alike.
Staff see only clients in houses assigned to them. A men's-home manager never sees a women's-home file, and per-client conflict-of-interest blocks go narrower still.
Overnight staff who see only logs. Kitchen staff who see only documents. Admins build roles with menu-item-level permissions, with no vendor ticket required.
Medication corrections void and restate, so the original entry is preserved. Shared client journals can't be silently deleted. The record is built for courts and audits.
A system-wide, field-level audit log records who changed what and when, across every module, alongside each client's own journey history.
[ Access and permissions ]
Axon separates organizational hierarchy, house assignment, and per-record visibility, so a whole team can work in one system without widening who sees what.
Admin, Manager, and Coordinator tiers plus fully custom roles, so a whole team works in one system without widening who sees what.
Beyond role and house, individual records carry their own audience, set by the person who created them.
Reports move draft to review to finalized with inline comments. Nothing reaches a court or funder without a person signing off, and the disclosure travels with it.
Corrections void and restate rather than overwrite. The original entry stays in the record, which is what makes it usable in a court or an audit.
[ AI governance ]
Care records need a higher bar than generic chat. Axon treats every AI query, draft, and output as a governed surface.
01
Client records, queries, and documents are never used to train the underlying models, and are not retained by them.
02
The assistant answers from your organization's records, never the open web. Missing data is flagged, not fabricated.
03
The AI filters, retrieves, and drafts. It does not make clinical suggestions or medication recommendations, by explicit design.
04
Reports move draft → review → finalized, with inline comments. Nothing reaches a court or funder without a person signing off.
05
Every AI-assisted report carries a disclosure note for its recipients, so courts, boards, and funders know how it was produced.
06
Uploaded documents and user text are treated as data, never as instructions, with strictly structured outputs on every call.
[ Security review ]
Architecture, data handling, subprocessors, and controls, ready for vendor diligence.
Clear contractual handling for client data: retention, deletion, and privacy commitments.
Access, change management, logging, and monitoring controls independently audited, with third-party HIPAA certification.
Two-factor authentication today; passkey and biometric sign-in on mobile; admin-owned access reviews.
[ FAQ ]
A practical starting point for executive directors, boards, and IT reviewers evaluating Axon Health.
No. Client records, queries, and documents are processed only to answer your request and are never used to train the underlying models.
No. Visibility is scoped by role and house assignment, medication access is granted explicitly, and admins can block a specific staff member from a specific client entirely.
Axon Health runs on AWS, with each organization's records in their own logical database. Deployment specifics and data-residency requirements are reviewed during security discovery.
Yes. The system-wide change log, per-client journey history, and section-by-section PDF exports support legal requests, incident review, and funder audits.
Deleted records follow a soft-delete convention with retention windows up to 20 years, matching child-welfare and legal record-keeping requirements.
We support technical and procurement reviews with documentation on architecture, controls, privacy, and data handling. Bring your compliance team to the first call.
Talk with us about your access model, ministry requirements, AI policies, and review path.