Trust & compliance
Security & Trust
AxonGrid is engineered for utility-grade security: Australian data residency, mandatory MFA, organizational identity verification, and zero-trust infrastructure for high-consequence grid operations.
Platform access
Identity & Access Controls
Every user authenticates with their own organizational email, verified ownership, and a mandatory authenticator app. Personal inboxes and unverified accounts cannot reach grid data.
Enforced
Mandatory TOTP MFA
No grid maps or optimization results without a 6-digit authenticator code.
- •Google Authenticator and Microsoft Authenticator compatible
- •Enrollment required before platform access
- •JWT tokens issued only after MFA verification
Enforced
Organizational Email Only
Customers register with their own utility domain — not personal inboxes.
- •Work emails such as you@powercorp.gov.au accepted
- •Consumer providers (Gmail, Yahoo, Outlook.com, etc.) blocked
- •Optional domain allowlist for pilot deployments
Enforced
Email Verification
Every new account must prove ownership of the organizational address.
- •One-time passcode sent on registration
- •Verified before MFA setup begins
- •Re-checked on sensitive auth operations
Enforced
Session Inactivity Timeout
Idle sessions expire automatically — aligned with utility operator expectations.
- •Default 6-hour inactivity window (configurable 4–8 hours)
- •Refresh tokens revoked after inactivity threshold
- •Re-authentication with MFA required to resume
Enforced
Brute-Force Lockout
Account and IP protection against credential stuffing and password guessing.
- •5 failed attempts trigger a 15-minute lockout
- •Applies to both account email and source IP
- •Lockout enforced across login, OTP, and MFA steps
Enforced
Login Audit Logging
Full visibility into every authentication attempt for security operations.
- •IP address, timestamp, and device/user-agent recorded
- •Success and failure events with reason codes
- •Queryable audit trail for compliance review
How sign-in works
Secure Access Journey
Customers use their utility domain — for example operator@powercorp.gov.au — not an AxonGrid address and not a personal Gmail or Yahoo account.
Register with organizational email
Use your utility or organization work address (e.g. you@yourutility.com). Personal providers such as Gmail, Yahoo, Hotmail, and Outlook.com are blocked.
Verify your email
A one-time code confirms you control the address before MFA enrollment.
Enroll mandatory MFA
Scan a QR code with Google Authenticator, Microsoft Authenticator, or any TOTP app. Grid maps and optimization data stay locked until MFA is active.
Sign in with password + 6-digit code
Every session requires your authenticator code after password verification.
Data residency
Institutional-Grade Data Sovereignty
AxonGrid is built on a foundation of absolute data residency. To ensure the security and sovereignty of critical national infrastructure data, 100% of our computation and storage takes place within the AWS Sydney (ap-southeast-2) Region.
We guarantee that sensitive grid telemetry and simulation artifacts never leave the Australian geographic perimeter. This regional isolation ensures compliance with national security guidelines and local data protection regulations.
We chose AWS Sydney (ap-southeast-2) for maximum and continuous availability — a stable, sovereign foundation for pilot and early-production workloads close to Australian grid operators.
Final product development will add local data residencies in additional regions so each deployment can meet its own jurisdictional and availability requirements.
Infrastructure
Zero-Trust Architecture
AxonGrid employs a zero-trust, VPC-isolated architecture designed for high-consequence energy environments — layered network isolation, encryption, identity controls, and immutable audit trails.
Network Isolation
Core Julia compute clusters operate in air-gapped private subnets with zero internet ingress/egress. AWS communication uses private VPC Endpoints only.
Encryption at Rest & in Transit
AES-256 encryption with AWS KMS Customer Managed Keys (CMK). All sessions secured via TLS 1.3.
Identity Sovereignty
Mandatory MFA, organizational email verification, and role-based access keep control with the utility operator. Enterprise OIDC and SAML 2.0 federation supported for SSO.
Immutable Auditing
Every simulation, login, and administrative action recorded in encrypted audit logs for full traceability and compliance reporting.
Operational Security
Workspace Isolation: each customer workspace is logically isolated with independent storage and access control boundaries.
Role-Based Access: organization roles (Grid Operator, Planning Engineer, Reliability Engineer, Admin, Viewer) scope platform capabilities per user.
Grid Data Protection: grid maps and optimization endpoints require an MFA-verified session — unauthenticated or MFA-pending users cannot view network topology.
Deployment Flexibility: AxonGrid supports cloud, private cloud, and on-prem deployment options for sensitive grid environments.
