Excellent Security. Built for Small Business.
Identity, permissions, audit chain, and DB row integrity — all on the same hardware-rooted stack that Fortune 500s use, priced for the company you are today. Other vendors hand small teams four bills (Okta + Auth0 + Vault + SIEM) and a hiring requisition for an IAM specialist. We ship it as one platform — passkey login, AI-described permissions, sealed audit log, 10-second contractor offboarding — free until you outgrow the General tier. Regulators verify your records themselves; attackers leave a chain entry they cannot forge.
Where Security & Auth breaks today
Cost of a basic security stack
Okta + Auth0 + HashiCorp Vault + a SIEM is the textbook stack — and the textbook is written for enterprises. For a 10-person team, the same tools quietly consume $50K+/year before a single engineer is hired to run them.
$50K+/yr — typical SMB stack cost · vendor list-price aggregation, 2025
Departed-employee credential debt
Small businesses rarely have a dedicated IT role. When a contractor or employee leaves, credentials linger across SaaS for weeks — every one of them is a free side-door into the company's data.
75% — of SMBs cite departed-user access as their top risk · Verizon DBIR 2024
Insider mistakes & audit-trail gaps
Without a tamper-evident log, a single confused employee — or a single bad actor — can wipe records and the business has no way to reconstruct what happened. Insurance and SOC 2 increasingly require this even at SMB scale.
SOC 2 / ISO 27001 — now demanded by enterprise customers even from 5-person vendors
Three patents, deployed against this industry's threat model
Each of Axowl's three filed patents maps to a specific structural failure mode in Security & Auth. Together they form a single, end-to-end defense.
Hierarchical Distributed Trust Fabric — Workstation (L1) · SaaS (L2) · Sealed archive (L3) — no L1 hardware required to start
Owner workstation forms L1 via FIDO2 passkey (no hardware token purchase needed — Mac Touch ID, Windows Hello, or phone biometric all qualify at the General tier). Axowl SaaS serves as L2. The sealed archive in a separate region forms L3. Day-one deployment costs zero — the General tier runs on AWS Free Tier infrastructure. Upgrade to vTPM at Standard tier when the company crosses ~100 employees, without re-architecting.
Transition-Sealed Integrity System — Every action sealed — even the founder cannot rewrite history
Each login, permission grant, vendor access, and admin action is sealed in real time. When a customer asks for a SOC 2 letter, a vendor for a security questionnaire, or insurance for an incident timeline — you answer in seconds, not weeks. A disgruntled departing employee cannot remove their own trail because the seal is one-way and mirrored to L3.
Pre-grant LLM Conflict Verification — Permissions you can describe in one sentence
Most SMB owners cannot write IAM JSON, do not want to learn SAP role keys, and cannot afford a Workday admin. Axowl's AI permission lets the owner type: "Finance can approve invoices under $5,000, no one but me can change payroll" — the platform translates to enforced scopes, blocks toxic combinations (self-approval, payroll + audit-log write) at grant time, and explains the result back in plain English.
Deployment that fits the threat model
Most SMB customers start on the General tier (free up to a generous threshold; passkey + AI permission + sealed audit included). Companies cross to the Standard tier (vTPM, regulator-grade audit) when a B2B customer audit, SOC 2 push, or 100-employee mark arrives — typically 18–36 months in.
Recommended tier: T0 · General → T1 · Standard
Deployment path: AWS Free Tier (General) → vTPM (Standard) · zero ops
Operational detail: Sign in with a passkey, paste your team email domain, and bring your identity provider over SSO or SCIM 2.0. Enterprise systems connect through the SAP, Oracle, and Salesforce connectors. The Free tier stays free under the included usage; upgrading is a single line item — no migration, no replatform.
Three concrete deployments
One-hour onboarding for a 10-person startup
Founder enrolls a passkey, connects Google Workspace, sets four AI-described permission groups (Owner / Engineering / Sales / Contractor). Every employee onboards with passkey-only — no password to reset, no MFA app to manage, no IT helpdesk needed.
Contractor offboarding in 10 seconds
Mark a user inactive in Axowl and the record is sealed the moment it happens — who did it, when, and on what device. Your IdP and connected systems read that state instead of a spreadsheet, so the answer to 'does she still have access?' is one query, not an afternoon.
Customer security questionnaire answered same-day
An enterprise customer sends a 60-question security questionnaire. Pull a sealed audit-log export, attach the SOC 2 readiness report Axowl generates, and answer in one afternoon — not the usual two-week scramble that loses deals.
Versus what's deployed today
Today — Okta + Auth0 + Vault + SIEM at list price
Four separate vendors, four invoices, four consoles, and at least one dedicated IT hire to keep them in sync. The economics simply do not work for a 10–100 person team — most SMBs end up running with one of the four and quietly accepting the risk on the other three.
With DPSM — Axowl DPSM
One platform, one console, one bill — free at the General tier and priced for the company you are today, not the enterprise you might become. AI permission removes the need for an IAM specialist. Sealed audit removes the need to bolt on a SIEM. Passkey-first removes the need to buy hardware tokens.
Standards & regulatory frameworks aligned
- SOC 2 Type II readiness
- ISO 27001 readiness
- GDPR Article 32 (technical measures)
- HIPAA Security Rule (with Healthcare add-on)
- PCI DSS 4.0 SAQ-A (with Stripe integration)
- Cyber Essentials (UK)