Secure by design
How AxleGrid is secured, and how you can check it.
Trust is easier to keep when the system is built for it. Avior is being built as a real multi-tenant SaaS platform from day one, with security and auditability treated as product features rather than a questionnaire to survive.
What is built
Six controls, in the codebase today.
Each one is in the AxleGrid codebase now and can be shown on a walkthrough. Nothing on this page is a plan.
Tenant isolation in the query layer
Every tenant-owned table carries a tenant id and a global query filter; a record from another tenant reads as absent, never as forbidden. Isolation is covered by automated tests on every build.Append-only audit ledger
Every change to a tenant record is written to an Azure SQL ledger table — append-only and tamper-evident — with who, what, when and the before and after values, filterable and exportable by the tenant’s own auditors.Hash-chained evidence
Each photo or document a fitter uploads is SHA-256 hashed and linked to the previous item on the job. The bundle reports whether the chain is intact and which checkpoints are complete before a job can be billed.Scoped roles, explained
Permissions are granted by role at a point in the organisation tree, with start and end dates and a reason. “Explain access” answers why any person can or cannot do any action, and a role can be previewed before it is assigned.Cost and margin hidden by policy
Cost, margin and rate-card visibility is a policy on the role, not a checkbox in a screen. The access model answers it for every person today, and it is applied to each pricing field as pricing comes into the product.Notifications you control
Every notification is a projection of an audited event. People switch non-critical ones off and set quiet hours; safety-critical alerts always arrive. Nothing is sent that the delivery record does not show.
Operating controls
How the platform is run.
- Hosting and data residency
- Microsoft Azure, UK West region, on a subscription owned by Avior IT Solutions. Databases are Azure SQL; evidence files are private blob storage with per-tenant paths and retention dates.
- Secrets
- Connection strings and credentials live in Azure Key Vault and reach the application as Key Vault references. They are not in code, configuration files or documentation, and the deployment scripts never print them.
- Change control
- Every change is a reviewed commit with a build and test run. Database changes are versioned migrations, applied and rolled back in an automated round trip before they reach an environment.
- Monitoring
- Metric alerts on API errors, Console errors, database availability and storage availability route to a named on-call contact.
- Public links
- Customer location links are single-purpose, expire, and are revocable by the dispatcher. They expose no staff data.
- Certifications
- None yet. The Cyber Essentials Plus evidence pack and a SOC 2 Type 1 readiness assessment are on the 2027 roadmap. Until then the controls above are the claim, and they can be inspected.
Verify it yourself
Ask for a walkthrough, not a questionnaire.
In one session we show the audit ledger for a job you choose, the evidence bundle with its chain check, explain-access for one of your people, and the compliance pack for a period. If a written security questionnaire is required, we answer it against these same controls. The same records are what produce a contract pack for a fleet customer.
Security walkthrough
Pick a job. We will show you its whole history.
The fastest way to assess this is to watch the ledger, the chain check and explain-access run against a real record rather than read about them.