Enterprise Trust & Security Architecture

Security, Governance & Data Protection

Axtrelis Forge operates high-throughput sovereign cloud infrastructure for enterprise generative media pipelines. We enforce strict cryptographic isolation, zero-retention data policies, and continuous compliance.

Zero Model Training Policy

Customer prompts, seed images, audio inputs, and generated video renders are strictly processed for generation delivery. We never use customer data to train, fine-tune, or evaluate foundation AI models.

High-Entropy Token Hashing

API tokens (vf_live_...) are generated via CSPRNG with 256 bits of entropy. Keys are displayed once upon creation and stored exclusively as cryptographic SHA-256 digests in Postgres.

Edge Encryption & Hardening

All communications enforce TLS 1.3 encryption with strict HSTS (63,072,000s preload), automated Let's Encrypt certificate renewal, OWASP-compliant secure headers, and isolated reverse proxies.

Two-Phase Commit (2PC) Ledger

All credit deposits and dispatches use row-level database locking with atomic reservation and settlement guarantees. Any rendering defect or timeout is instantly refunded in full with zero ledger drift.

Vulnerability Disclosure & RFC 9116

We welcome responsible security research. If you discover a potential vulnerability in Axtrelis Forge infrastructure, please report it to our security operations group. We acknowledge valid reports within 24 hours.

Contact: mailto:[email protected]
Canonical: https://forge.axtrelis.com/.well-known/security.txt
Preferred-Languages: en, de
Corporate Entity & Jurisdiction
Axtrelis Forge is developed and underwritten by Axtrelis LLC (Wyoming, USA // Dresden, Germany Hub).
All commercial transactions are governed strictly under B2B commercial code (§ 14 BGB) and US commercial law.