Trust & compliance

Security & Trust

AxonGrid is engineered for utility-grade security: Australian data residency, mandatory MFA, organizational identity verification, and zero-trust infrastructure for high-consequence grid operations.

Platform access

Identity & Access Controls

Every user authenticates with their own organizational email, verified ownership, and a mandatory authenticator app. Personal inboxes and unverified accounts cannot reach grid data.

Enforced

Mandatory TOTP MFA

No grid maps or optimization results without a 6-digit authenticator code.

  • •Google Authenticator and Microsoft Authenticator compatible
  • •Enrollment required before platform access
  • •JWT tokens issued only after MFA verification

Enforced

Organizational Email Only

Customers register with their own utility domain — not personal inboxes.

  • •Work emails such as you@powercorp.gov.au accepted
  • •Consumer providers (Gmail, Yahoo, Outlook.com, etc.) blocked
  • •Optional domain allowlist for pilot deployments

Enforced

Email Verification

Every new account must prove ownership of the organizational address.

  • •One-time passcode sent on registration
  • •Verified before MFA setup begins
  • •Re-checked on sensitive auth operations

Enforced

Session Inactivity Timeout

Idle sessions expire automatically — aligned with utility operator expectations.

  • •Default 6-hour inactivity window (configurable 4–8 hours)
  • •Refresh tokens revoked after inactivity threshold
  • •Re-authentication with MFA required to resume

Enforced

Brute-Force Lockout

Account and IP protection against credential stuffing and password guessing.

  • •5 failed attempts trigger a 15-minute lockout
  • •Applies to both account email and source IP
  • •Lockout enforced across login, OTP, and MFA steps

Enforced

Login Audit Logging

Full visibility into every authentication attempt for security operations.

  • •IP address, timestamp, and device/user-agent recorded
  • •Success and failure events with reason codes
  • •Queryable audit trail for compliance review

How sign-in works

Secure Access Journey

Customers use their utility domain — for example operator@powercorp.gov.au — not an AxonGrid address and not a personal Gmail or Yahoo account.

1

Register with organizational email

Use your utility or organization work address (e.g. you@yourutility.com). Personal providers such as Gmail, Yahoo, Hotmail, and Outlook.com are blocked.

2

Verify your email

A one-time code confirms you control the address before MFA enrollment.

3

Enroll mandatory MFA

Scan a QR code with Google Authenticator, Microsoft Authenticator, or any TOTP app. Grid maps and optimization data stay locked until MFA is active.

4

Sign in with password + 6-digit code

Every session requires your authenticator code after password verification.

Data residency

Institutional-Grade Data Sovereignty

AxonGrid is built on a foundation of absolute data residency. To ensure the security and sovereignty of critical national infrastructure data, 100% of our computation and storage takes place within the AWS Sydney (ap-southeast-2) Region.

We guarantee that sensitive grid telemetry and simulation artifacts never leave the Australian geographic perimeter. This regional isolation ensures compliance with national security guidelines and local data protection regulations.

We chose AWS Sydney (ap-southeast-2) for maximum and continuous availability — a stable, sovereign foundation for pilot and early-production workloads close to Australian grid operators.

Final product development will add local data residencies in additional regions so each deployment can meet its own jurisdictional and availability requirements.

ap-southeast-2Australian data perimeterNational infrastructure complianceMaximum availabilityLocal residency roadmap

Infrastructure

Zero-Trust Architecture

AxonGrid employs a zero-trust, VPC-isolated architecture designed for high-consequence energy environments — layered network isolation, encryption, identity controls, and immutable audit trails.

Network Isolation

Core Julia compute clusters operate in air-gapped private subnets with zero internet ingress/egress. AWS communication uses private VPC Endpoints only.

Encryption at Rest & in Transit

AES-256 encryption with AWS KMS Customer Managed Keys (CMK). All sessions secured via TLS 1.3.

Identity Sovereignty

Mandatory MFA, organizational email verification, and role-based access keep control with the utility operator. Enterprise OIDC and SAML 2.0 federation supported for SSO.

Immutable Auditing

Every simulation, login, and administrative action recorded in encrypted audit logs for full traceability and compliance reporting.

Operational Security

Workspace Isolation: each customer workspace is logically isolated with independent storage and access control boundaries.

Role-Based Access: organization roles (Grid Operator, Planning Engineer, Reliability Engineer, Admin, Viewer) scope platform capabilities per user.

Grid Data Protection: grid maps and optimization endpoints require an MFA-verified session — unauthenticated or MFA-pending users cannot view network topology.

Deployment Flexibility: AxonGrid supports cloud, private cloud, and on-prem deployment options for sensitive grid environments.

Questions about security?

Our team can walk through architecture diagrams, data residency guarantees, identity controls, and enterprise SSO integration for your organization.