Platform & security

Your records. Your deployment. Your region.

Weld records are safety-critical evidence with a decades-long life. The platform that holds them should be boring in all the right ways: isolated, encrypted, audited, and honest about what’s attested versus what’s on the roadmap.

Architecture

Isolation is the architecture, not a feature flag.

A dedicated stack per customer

Every customer runs their own environment on Microsoft Azure — own database, own key vault, own storage, own compute. There is no shared data plane between customers, so there is nothing to “logically separate.”

Region pinned, in writing

Your deployment lives in the Azure region you choose, with a written commitment that your data doesn’t move. Sovereignty-sensitive programs can go further — up to deployment into your own Azure subscription on our top arrangement.

Your subdomain, day one

Each company runs at its own address — yourcompany.maxtrax.io — with support for vanity domains on your own DNS when procurement wants your name on the door.

Encrypted, everywhere

TLS in transit, encryption at rest, secrets in managed key vaults, and passwordless managed identities between services — credentials aren’t lying around to leak.

Identity & access

Security is never an upsell.

SSO on every plan

Federate to your identity provider — OIDC or SAML — on any plan. Single sign-on is basic identity hygiene, and it’s included.

MFA for every user

Multi-factor authentication is included and expected, for internal and external users alike.

Roles with real scoping

A role hierarchy from system administration down to read-only, with per-user scoping by project, contractor, and inspection type — external parties see exactly what they should, and their access is flagged and audited.

An audit trail that names things

Actor, action, target, consequence, timestamp — at weld, drawing, project, and company scope. Attestations name the signer and the meaning. Configuration changes are audited too.

Resilience

Built to be restored, not just backed up.

Tiered recovery objectives

Recovery point and time objectives scale with your service level, up to geo-redundant backup and warm-standby arrangements for the most demanding programs.

Rehearsed restores

A disaster-recovery runbook with recorded restore testing — because a backup you’ve never restored is a hope, not a plan.

Migration with proof

Cutovers are rehearsed on real production data with checksum-verified reconciliation — and go-live ships with a signed reconciliation report, not a shrug.

Status you can check independently

The public status page will run on infrastructure independent of the platform itself — so during an incident, the page telling you about it stays up.

Compliance

An honest roadmap beats a vague badge.

We’d rather tell you exactly what’s in place today and what’s dated on the roadmap than wave “enterprise-grade” at your security team.

In place at early access

  • Dedicated isolated deployment per customer
  • Encryption in transit and at rest
  • SSO federation (OIDC/SAML) + MFA, every plan
  • Role-based access with entity-level scoping
  • Comprehensive audit logging, config included
  • Region residency, committed in writing
  • DR runbook with recorded restore testing
  • Documented vulnerability management

Dated on the public roadmap

  • SOC 2 Type II attestation path — 2027
  • ISO 27001 certification path — 2027
  • Recurring independent penetration testing — 2027
  • SCIM user provisioning — 2027
  • OAuth2 API platform for third-party integration — 2027
  • Customer-facing audit & bulk-export APIs — 2027

We publish dates, not adjectives — and we don’t claim a certification until the certificate exists. See the roadmap for the full picture.

Data freedom

Your data is yours. Exit is a feature.

Governed views, scheduled exports in industry-standard formats, and BI-tool embed that works with whatever analytics stack you run. A platform confident in its value doesn’t need to hold your evidence hostage.

Bring your security questionnaire.

We like the hard questions — isolation, residency, identity, recovery. Ask them before your procurement team has to.