Skip to Content
Trust & Security Center

Enterprise-Grade Security & On-Premise Control

Built around OWASP Top 10 standards to meet the strictest corporate security, data sovereignty, and compliance policies.

  • OWASP Compliant
  • On-Premises Deployment
  • SSO / RBAC Ready
  • Zero External Data Leaks
OWASP Top 10 — Build-Time Requirement

The OWASP Top 10 is the industry-standard awareness list of the most critical security risks to web applications. EAXEE is engineered to address every category in the OWASP Top 10 — not as a marketing claim, but as a build-time requirement that informs how the platform is architected, deployed, and operated. The grid below maps each OWASP Top 10 category to the corresponding EAXEE control.

OWASP Top 10 → EAXEE Control Mapping

Each OWASP category mapped to the corresponding EAXEE engineering control — scanned at a glance, not buried in dense paragraphs.

A01:2021

Server-Side RBAC, Default Deny

Role-based access enforced server-side through the Administration module. Default deny — permissions configurable at object, relationship, and property level.

A02:2021

TLS in Transit, Encrypted at Rest

TLS for all client-server traffic. Sensitive data at rest encrypted with industry-standard ciphers. On-prem lets you apply your own key-management practices.

A03:2021

Parameterized Queries, Schema Validation

Parameterized queries throughout the data layer — no string-concatenated SQL. Server-side schema validation rejects malformed payloads before processing.

A04:2021

Threat-Modeled, Secure by Default

Threat modelling during platform design. Secure-by-default configuration — no feature ships enabled-by-default with elevated privileges.

A05:2021

Hardened Defaults, Security Headers

Hardened default deployment with CSP, HSTS, X-Content-Type-Options, and X-Frame-Options. Error messages never leak stack traces or internal paths.

A06:2021

Dependency Inventory, Patch Cadence

Dependency inventory maintained and reviewed. Security patches applied on a regular cadence. On-prem customers schedule updates against their own windows.

A07:2021

SSO, MFA, AD — Credentials Stay With You

Authentication delegated to your identity provider via SSO, MFA, and Active Directory. Credentials never stored in EAXEE. Account lockout on repeated failures.

A08:2021

Signed Releases, Auditable Changes

Build pipeline verifies artifact integrity with signed releases. Administration module exposes an audit log of privilege, repository, and meta-model changes.

A09:2021

Security Events Logged, SIEM-Ready

Login, privilege change, repository access, and bulk Impex exports are logged. On-prem logs never leave your environment — feed directly into your SIEM.

A10:2021

Allow-Listed Destinations, No URL Fetch

Outbound network calls restricted to allow-listed destinations. Integration targets (ServiceNow, Exchange) configured explicitly by administrators — not by end users.

On-Prem Deployment — Compliant with Your Organization's Security Policy

EAXEE can be deployed on-premises inside your organization's network. On-prem deployment means the platform, its data, and its logs never leave your environment — there is no external SaaS dependency. This makes EAXEE suitable for organizations whose security policy and practices prohibit external SaaS hosting, including regulated industries, government bodies, and Saudi PIF companies operating under data-residency requirements.

EAXEE deployed inside the customer's private cloud / enterprise firewall

Enterprise Firewall

Identity Provider

SSO · MFA · Active Directory

EAXEE Platform

App · Database · Logs

Integrations

ServiceNow · Exchange

Air-Gapped Support

Deployable inside your private cloud or enterprise firewall with no outbound internet dependency. Patches and updates can be staged through your own change-management process.

Identity Integration (SSO / SAML / OAuth)

Delegated authentication to your existing identity provider — credentials never stored in EAXEE. Supported providers listed below.

Full Data Ownership

Your EAXEE database runs on infrastructure you control. Database isolation is explicit — no shared tenancy, no cross-customer data plane.

Supported Identity Providers

Delegated authentication — credentials never stored in EAXEE.

  • Microsoft Active Directory
  • Microsoft Entra ID (Azure AD)
  • Okta
  • Ping Identity
  • Keycloak
  • SAML 2.0 / OAuth 2.0 (any compliant IdP)

Identity & Integration Layer

EAXEE integrates with your existing enterprise identity and integration infrastructure rather than replacing it. This means authentication, authorization, and mail flow can be governed by your organization's existing security policy.

SSO (Single Sign-On) — delegated authentication to your identity provider

MFA (Multi-Factor Authentication) — enforced through your identity provider

Active Directory — user and group lookup against your AD infrastructure

Microsoft Exchange — outbound notifications and reports through your mail server

ServiceNow — integration with your ITSM workflows

Need to Review Our Security Architecture?

Download our full Security Whitepaper or schedule a technical review with our engineering team. We'll walk through OWASP Top 10 controls, on-prem deployment, identity integration, and the questions your security team actually asks.

Response within 24 business hours • No NDA required for initial review

100 users
Free License First 100 users · T&C apply