Trust center

Security

We design our products to protect customer workspaces, limit provider access, and make security concerns easy to report.

Effective 18 July 2026 Axii LLC · Republic of Kosovo

Our approach

Axii LLC applies layered administrative, organizational, and technical safeguards appropriate to the nature of our business software. Our security program evolves with our products, risks, and legal obligations.

We do not claim that any internet service is completely secure. We monitor for issues, prioritize meaningful risks, and work to remediate confirmed vulnerabilities responsibly.

Core safeguards

  • encrypted HTTPS transport for public product communications;
  • authenticated access and authorization checks at service boundaries;
  • tenant isolation and permission-aware access to Skedari matters, folders, and documents;
  • least-privilege provider permissions and scoped add-in access;
  • verification of provider and service identities before processing integration requests;
  • controlled audit and operational logging that avoids mailbox content, access tokens, message subjects, and recipient lists;
  • secure key handling, rotation procedures, and the ability to disable integrations during an incident; and
  • backups, monitoring, dependency maintenance, and incident response appropriate to each production service.

Skedari add-in security

The Skedari Outlook and Gmail integrations are designed around an explicit user action. They use the minimum practical provider access to read the currently selected message and file it into a destination the user is permitted to access.

Microsoft and Google provider tokens remain in request memory and are not stored by the add-on gateway. The gateway sends a separately signed, short-lived assertion to the Skedari tenant service, where tenant and product-entitlement rules are enforced again.

Report a vulnerability

Send security reports to support@axii-llc.com. Please do not send sensitive customer content in the initial report.

A helpful report includes:

  • the affected product, domain, and feature;
  • clear reproduction steps and potential impact;
  • relevant request identifiers or sanitized evidence; and
  • a safe way to contact you for follow-up.

We aim to acknowledge credible reports within three business days. Do not access or alter data that does not belong to you, disrupt production services, use social engineering, or publicly disclose a potential issue before we have had a reasonable opportunity to investigate and fix it.

Security and privacy contacts

Security reports: support@axii-llc.com
Privacy requests: support@axii-llc.com
Product support: support@axii-llc.com