Skip to content

Security

TaxCollector23 edited this page Oct 10, 2026 · 3 revisions

Security

AXIOM is in beta. Review the local boundary and release artifact before using it with sensitive projects.

Local boundary

  • The daemon binds to 127.0.0.1 by default.
  • Non-loopback binding requires explicit --allow-network.
  • Daemon routes are read-only and expose local summaries, hardware, actions, and visible tools.
  • AXIOM is not an account service or hosted backend.

Never commit

  • Passwords
  • API keys
  • Access tokens
  • Private datasets
  • GPG private keys

axiom tools doctor reports credential-reference presence, not authentication, and AXIOM does not store API-key values.

Release verification

Use the published SHA256SUMS file when available. Do not treat a planning estimate, tool-presence result, or Headroom integration as a security or performance guarantee.

Reporting vulnerabilities

Follow the repository security policy and use GitHub's private advisory process for sensitive reports.

Clone this wiki locally