Frequently asked questions
General
What is Axowl?
Axowl is an all-in-one identity platform covering Authentication (Passkey, Social, MagicLink, KYC), Authorization (Permission Engine with SCIM/SSO), and Notarization (hardware-rooted cryptographic sealing) — a typical identity stack plus a tamper-proof audit ledger, in one platform.
How is Axowl different from typical identity providers?
Most identity providers stop at authentication and basic RBAC. Axowl adds a third layer — Notarization — which seals every identity event and business action into a hardware-rooted hash chain archived to immutable storage. This makes insider threats and log tampering cryptographically impossible, not just policy-controlled.
Do I need to replace my existing IdP?
No. Axowl can sit on top of your existing IdP (Entra ID, Okta, Keycloak) via SCIM + OIDC federation. You can adopt it incrementally — start with the Permission Engine and add Notarization later. No rip-and-replace required.
Pricing
Is there a free tier?
Yes. The General tier (Tier 0) is free for up to 3 members and includes Passkey authentication, social login, and basic permission management. No credit card required.
How is pricing calculated?
Pricing is based on active members per organization and the Security Tier selected (General → Standard → Defense → Iron). Volume discounts apply for enterprise contracts. See full pricing →
Do you offer enterprise contracts?
Yes. Enterprise plans include dedicated SLAs, on-premises deployment (Iron-2), custom SCIM connectors, SSO, and a dedicated Customer Success Manager. Contact sales →
Security
What does 'hardware-rooted' mean?
At Tier 1 (Standard), every event is signed inside a vTPM (virtual TPM) — the private key never touches the host OS. At Tier 2 (Defense) and above, signing moves into a Nitro Enclave (TEE). At Tier 3 (Iron), we use FPGA-based PUF hardware — physically unclonable, impossible to extract via software.
Where is my data stored?
Axowl follows a Brain & Permit model: we never store your cloud or ERP keys. Sealed audit records are archived to Cloudflare R2. For Iron-2 on-premises deployments, all data stays entirely within your own network — zero egress.
Is Axowl SOC 2 / ISO 27001 certified?
We are currently in the SOC 2 Type II audit process. Our architecture was designed from day one to satisfy NIST SP 800-63-3 (AAL3) and ISO 27001 controls. Contact us for the current compliance report.
Technical
How does SCIM provisioning work?
Connect your IdP (Entra ID, Okta, Keycloak, etc.) to Axowl's SCIM 2.0 endpoint. When you add a user to a group in your IdP, Axowl automatically creates a ConnectedId, assigns the mapped Role, and generates a permission snapshot — no manual sync needed.
What is a SignedPermit?
A SignedPermit is a short-lived (30s–5min) RS256-signed JWT that Axowl issues after verifying a ConnectedId's permissions. Your Plugin (running in your environment) verifies the signature and executes the action — Axowl never executes on your behalf or stores your API keys.
Can I run Axowl on-premises?
Iron-2 is an on-premises FPGA server appliance deployable inside your own data center or air-gapped network. Designed for central banks, defense contractors, and regulated healthcare providers. Contact us for a PoC →