Axiom
Axiom is a secure, scalable communications and task management platform with cryptographically-signed verification of media, delivering truth and trust in an age of AI spoofing. Communicate with and coordinate dispersed teams to deliver effects at reach.
Features
- End-to-end encrypted messaging, voice and video calls
- Cryptographically-signed verified media
- Biometric user enrolment
- Identity verification
- Instantaneous digital payments
- Shareable map layers with UNOCHA and NATO symbology
- Location tracking
- Autonomous or semi-autonomous drone command
- Dynamic target pack creation using verified images and videos
- Task management: create, assign and approve tasks
Benefits
- Verify anything in the real world: images, video, documents
- Communicate securely in 100+ languages
- Verify who you are communicating with
- Visualise the location of your teams and mark locations
- Coordinate, assign and track tasks
- Send payments across borders, instantly
- Task drones in seconds, autonomously or semi-autonomously
- Communicate in black spots with resilient Iridium satellite communications
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 6 4 6 3 4 3 6 7 3 3 3 5 7 7
Contact
LABRYS TECHNOLOGIES LTD
Dan Davies
Telephone: +447904984897
Email: dan.d@labrys.tech
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Users can access Axiom via web, desktop (macOS and Windows), and mobile applications (Android and iOS). Mobile and desktop applications are supported on vendor-supported operating system versions only. The web application is supported on modern, vendor-supported browsers. Some device-specific capabilities are not available via the web application. Restricted or specialist environments may require additional configuration.
- System requirements
-
- Internet connectivity (broadband, mobile, or satellite)
- Vendor-supported Windows, macOS, Android, or iOS operating systems
- Device capable of running supported operating systems
- Device capabilities (optional): camera and microphone for voice, video
- Device capabilities (optional): location services for location-based features
- Device capabilities (optional): secure hardware module for media verification
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond to user support requests within 1 business day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We have an online customer support team which will respond to support tickets within one business day. The support help desk is serviced between 9am - 6pm UTC Monday - Friday.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide service documentation as standard to support users in getting started with Axiom. The application includes in-app guidance, hints, and contextual help to explain features and workflows. Remote onboarding and training can be provided, and onsite training is available where required. Training and enablement services are scoped and delivered subject to additional cost.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Authorised administrative users can export their data from the Axiom platform using available export functions. Where required, Labrys Technologies can provide assisted offboarding and support for large-scale data extraction at the end of the contract. Assisted offboarding services are subject to additional cost in accordance with the G-Cloud 15 SFIA rate card.
- End-of-contract process
- At the end of the contract, the customer may choose to renew or terminate the service. If the service is terminated, authorised users can export their data using the standard export functionality included in the service. Where additional offboarding support or assistance with large-scale data extraction is required, this can be provided by Labrys Technologies at an additional cost in accordance with the G-Cloud 15 SFIA rate card.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Axiom provides a high degree of functional parity across mobile and desktop platforms. Differences relate primarily to device-specific capabilities. Mobile applications support features such as biometric enrolment, hardware-backed security, background operation, and granular location services where supported by the device. Desktop applications provide the same core functionality but may not support all mobile device-specific capabilities and rely on the underlying operating system and hardware configuration.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Users interact with Axiom through a dedicated graphical user interface available via web, desktop, and mobile applications. The interface provides role-based access to secure communications, task management, mapping, and media verification features, with functionality adapting to the capabilities of the user’s device and platform.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service has been tested internally for compatibility with common assistive technologies, including screen readers and keyboard-based navigation, as part of routine quality assurance. No formal user testing has been conducted with assistive technology users.
- API
- Yes
- What users can and can't do using the API
-
Axiom provides internal, secure APIs to support integration with customer systems and workflows. The APIs are REST-based and documented using OpenAPI specifications.
API access is not publicly available and is enabled on a per-customer basis during contracting. Depending on the agreed scope, customers can integrate data, automate workflows, and interact with selected platform functions.
Initial service setup, structural configuration, and changes to core platform behaviour are not performed through a self-service API and are managed by Labrys Technologies or enabled following agreement. API endpoints, permissions, and capabilities are restricted according to contractual and security requirements. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise Axiom through configuration options and optional bespoke development. Configuration allows authorised customer administrators to tailor user roles and permissions, workflows, task structures, and operational settings within their workspace.
Additional customisation, integrations, or feature extensions can be delivered through scoped development agreed during contracting. All customisation activities are subject to security and governance controls and are quoted on a case-by-case basis. Customisation is performed either by authorised customer administrators (for configuration) or by Labrys Technologies (for bespoke development).
Scaling
- Independence of resources
- Axiom is designed to scale horizontally to support global usage, with resources dynamically allocated to meet demand. Customers are logically isolated within the service to ensure separation of data and workloads. Where required, Axiom can also be deployed in dedicated environments, including private cloud or on-premises deployments, with federated connectivity between instances. Dedicated or bespoke deployment models are subject to additional scoping and cost in accordance with the G-Cloud 15 SFIA rate card.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Axiom provides customers with visibility of service usage metrics relevant to their deployment. Metrics include licensed user counts, active users within a customer workspace, and usage information for core service features. Authorised customer administrators can view usage information to support operational oversight and licence management. Labrys Technologies also monitors service usage at a platform level for operational and security purposes.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Permissioned users can export their data from the Axiom service using supported client applications and available export functions. Users can download and retain files and media they have access to. Where large-scale data extraction or assisted offboarding is required, Labrys Technologies can provide support at additional cost in accordance with the G-Cloud 15 SFIA rate card.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- JPG
- GPX
- PNG
- ZIP
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- PNG
- JPG
- CSV
- TXT
- GPX
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Data in transit between client devices and the Axiom service is protected using industry-standard TLS 1.2 or higher. Application-level encryption is used to protect message content and media end-to-end where supported. Data in transit within the supplier environment is protected using encrypted service-to-service communication and mutual authentication.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Data in transit within the supplier environment is protected using encrypted service-to-service communication, mutual authentication, and transport-layer encryption to ensure confidentiality and integrity of internal network traffic.
Availability and resilience
- Guaranteed availability
- Subject to the terms of the SaaS Order Form, Labrys Technologies aims to provide 99.5% service availability per calendar month. Availability excludes planned maintenance, upgrades, and emergency maintenance. Planned maintenance is normally performed between 22:00 and 02:00 UK time with at least two business days’ notice. Reasonable endeavours are made to notify customers of emergency maintenance where possible.
- Approach to resilience
- Axiom is designed for resilience using redundant infrastructure, automated recovery mechanisms, and continuous monitoring to minimise service disruption. The service operates in a highly available cloud environment, with resilience measures appropriate to the agreed deployment model.
- Outage reporting
- Known service outages are communicated to customers by the Labrys Technologies support team using agreed communication channels, including email, with updates provided until service is restored.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Labrys Technologies secures the Axiom platform using strict access controls, including Role-Based Access Control (RBAC) with defined roles and authorisation policies. User actions are logged and audited for security and compliance, and regular access reviews are performed to ensure permissions remain appropriate. Management and support access is restricted to authorised personnel, protected using encrypted channels, and granted on a least-privilege, per-task basis.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Labrys Technologies implements robust information security policies under ISO 27001. The processes include risk management, strict access controls, incident response plans, and regular audits to ensure compliance and identify improvements. Policies are managed through a well-defined reporting structure, with security responsibilities ultimately owned at Board level by the CEO but directly delegated to the acting Chief Information Security Officer (CISO) who reports directly to the board and sits as part of the management team.
Cross-functional teams ensure compliance and integration across departments, maintaining a security-focused organisational culture. Employee training programs on security best practices are routine, ensuring awareness and adherence. Performance metrics and continuous monitoring via a SOC provide real-time insights into the effectiveness of the security framework, ensuring that deviations are promptly managed and rectified. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We use versioned deployable artefacts that can be tested and deployed independently. Changes are tracked using tickets that describe distinct pieces of work. All changes included in a release are assembled into a changelog for administrative visibility. Development changes are assessed for security impact as part of the development process, and any changes with potential security implications are reviewed by a panel that includes the CISO.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We use automated vulnerability scanning tools including GitHub Dependabot, Trivy, and other industry-standard solutions. Identified vulnerabilities are triaged by severity and either patched within the current deployment cycle or tracked for remediation. We use established threat intelligence sources, including CrowdStrike threat intelligence, to inform prioritisation.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use continuous monitoring and risk-based detection policies to identify potential security events. Logs are centrally collected and monitored by a 24x7 SOC. Alerts are investigated promptly, and any suspected compromise is handled in accordance with established incident response procedures.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Users can report security incidents via published contact channels, including a dedicated incident reporting form or email. All incidents are logged, investigated, and managed in accordance with internal incident handling procedures. Significant incidents are subject to post-incident review to identify root causes and improvement actions.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
We can support limited-time proof of concept deployments, whereby we work with your team to map out where Axiom can add value to existing operations and enable new capabilities.
All proof-of-concept exercises are limited to three months. All features are included. To qualify you must meet the minimum-order criteria.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Monday 24 June 2024
- What the ISO/IEC 27001 doesn’t cover
-
The scope statement for the Labrys ISO 27001:2022 covers all activities and locations of the company. Specifically
“The design, development, build & provision of Axiom, a secure workforce management platform delivered as a Software-as-a-Service (SaaS) solution to public and private sector clients. This is in accordance with the statement of applicability V2.0 dated January 2025. “
The Statement of Applicability used in the Labrys certification to ISO 27001:2022 contains no excluded clauses. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7cf792a6-9261-4cfe-b462-0c381e493c3c
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2983620a-6331-430e-83cc-613e109319e3
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-