← Back to AxiomGate

AUDIT REQUESTS / 2026-09-17

Your scope.
Your information.

This notice describes the public AxiomGate website and audit-intake surfaces. It is operational transparency, not legal advice. Do not include source code, credentials, secrets or confidential client data in a form, chat or email.

Controller and contact

AxiomGate, represented by Robin Svensson, is responsible for the website intake described here. For privacy questions or a rights request, contact [email protected]. Billing questions go to [email protected]; security disclosures go to [email protected].

What we collect and why

Depending on the purpose, processing is based on taking steps at your request before a contract, performing an agreed service, legitimate interests in security and abuse prevention, or consent where the interface asks for it. A request is not a marketing subscription.

Optional public Concierge AI

The optional Concierge accepts bounded questions about AxiomGate, audit packages and published methodology. When configured, bounded chat text is sent to OpenCode Zen; Google Gemini 2.5 Flash is a separate configured fallback. Otherwise the page uses deterministic local answers. Public chat is not stored by the website or lead database, but the selected provider processes the text under its own terms. Do not paste source code, credentials, secrets or customer data.

Service providers and transfers

Cloudflare provides DNS, edge delivery, email routing and, where configured, private object storage for delivery artifacts. Resend may deliver transactional email. Stripe processes payment details only when you choose Stripe Checkout. Frilans Finans receives the information required for an invoice only when you select that route. OpenCode Zen or Google Gemini receives only the bounded public Concierge conversation when that provider path is used. These providers may process data outside Sweden or the EEA under their own terms and transfer safeguards. Customer source is not sent to hosted models by the AxiomGate analysis path.

Billing and delivery

Swedish and Nordic billing is handled by Frilans Finans Sverige AB. EU and international B2B billing uses a direct invoice with the applicable VAT treatment and bank transfer instructions. Order requests are addressed to [email protected]; customer support and technical audit questions go to [email protected].

Delivery and storage

Submitting the form sends your request details to AxiomGate for storage and processing. When email delivery is configured, an order confirmation is sent through Resend using your delivery email and relevant order details. Stripe processes checkout and payment information only when you follow the Stripe payment link. Request submission alone does not start a source-code scan.

Order records, NDA receipts, correspondence and audit deliverables are retained separately from source snapshots. Source access and retention are agreed for each engagement. Request and support records are kept only as long as needed for the request, service, accounting, security or an active dispute; legal and accounting obligations can require longer retention. Temporary rate-limit hashes are process-local and are not part of the lead record.

A downloaded file remains in your downloads, copied data remains on your clipboard, and your mail service handles information you choose to send under its own terms. A mailto link cannot attach order.json automatically or confirm delivery. Closing the page clears its in-memory request.

Your choices

You may request access, correction, deletion, restriction, portability or object to processing where applicable. You may withdraw consent where processing relies on consent; this does not affect earlier lawful processing. Contact [email protected]. You may also complain to the Swedish Authority for Privacy Protection (IMY) ↗. We may retain information required for law, accounting, security or an active dispute.

Automated decisions

The teaser rate limit, public Concierge and indicative package recommendation do not decide your legal rights, access to essential services or eligibility. For the bounded audit tiers, scope validation, analysis, evidence packaging and delivery run automatically after verified payment; no human decides your rights or eligibility in that path. Enterprise Custom delivery requires human review because its scope is bespoke. No profiling or advertising audience is created by this website.

Local assets

Fonts, images and scripts are served with this website. It includes no advertising pixels, no third-party analytics and no embedded third-party media. A first-party, cookie-free conversion measurement module ships with the site but is inactive: no endpoint is configured, so no measurement event leaves your browser. This notice will be updated before it is enabled.