Access control
Role-based permissions, approval workflows, and least-privilege access for agents, data, and connected systems.
Trust
Caxion is built for governed AI work. This page summarizes how we approach security, compliance documentation, subprocessors, and ongoing updates.
Governance, access control, validation, and auditability are not optional add-ons. They are designed into how Caxion discovers, builds, connects, and measures AI use cases.
Role-based permissions, approval workflows, and least-privilege access for agents, data, and connected systems.
Encryption in transit and at rest, scoped integrations, and clear separation between customer content and platform operations.
Records for configuration changes, approvals, evaluations, and production activity so enterprise actions remain explainable.
Classify risk, validate before deployment, monitor performance, and retire agents with retained history.
Looking for legal terms? See the Privacy Policy, Cookie Policy, and Terms & Conditions.
Documentation and policies for security, privacy, and customer due diligence. Additional certifications and questionnaires can be shared under NDA where applicable.
Document
High-level description of Caxion’s security posture, product controls, and operational practices.
Document
How customer content, prompts, connection metadata, and logs are processed and retained.
Policy
How personal information is collected, used, and shared across the web app, native apps, and related Services.
Policy
How cookies and similar technologies are used on caxion.ai. The marketing site does not set optional tracking cookies.
Policy
The contractual terms governing access to and use of the Caxion Services.
Caxion uses carefully selected subprocessors to operate the Services. Categories and examples below describe current processing relationships and may be updated as the platform evolves. A more detailed current list is available on request at privacy@caxion.ai. See also the Privacy Policy.
| Subprocessor category | Purpose | Location |
|---|---|---|
| Infrastructure (Firebase / Google Cloud) | Application hosting, Cloud Functions, storage, identity, App Check, and related cloud infrastructure | United States |
| AI model providers (e.g. OpenAI, Anthropic, Google, xAI) | Processing of customer-initiated prompts, context, and related content to return model outputs; set of providers may change over time | Varies by provider |
| Email delivery (Resend) | Transactional email such as verification, resets, invites, and feedback acknowledgments | United States |
| Payments & entitlements (Apple / RevenueCat) | In-app purchase processing via Apple; subscription and entitlement status via RevenueCat | United States / Apple regions |
| Push notifications (APNs / FCM) | Delivery of push notifications to devices where enabled | Varies by platform |
Common questions about security, data handling, and trust.
Caxion processes data through its application infrastructure and approved subprocessors needed to operate the Services. Specific destinations can vary by feature and connected provider. See the Subprocessors tab and Privacy Policy for categories and examples.
Caxion does not use customer content to train generalized public models unless you provide explicit, separate permission for a defined purpose. Model providers process content to return outputs for your requests; their retention and training practices are governed by their terms and may change. See the Privacy Policy for details.
Connections require user or administrator consent. Access is limited to approved scopes, and credentials are stored with controls designed for enterprise use.
Email security@caxion.ai with details of the issue. Do not include sensitive production credentials in the initial report.
Caxion is available on the web at caxion.ai and as native apps for iPhone and iPad. Features may vary by device, plan, and region. This Trust Center provides security, privacy, and compliance materials for customers and prospects.
Material changes to trust documentation, subprocessors, and security communications will be recorded here.
September 9, 2026
Added a Cookie Policy for caxion.ai. The marketing site does not set analytics or advertising cookies and does not show a consent banner because there are no optional cookies to consent to.
August 5, 2026
Updated Privacy Policy and Terms & Conditions for web, iPhone, and iPad Services—including AI providers, voice, attachments, memory and retention, billing, and organization sharing. Subprocessor categories aligned.
July 22, 2026
Launched the public Trust & Security page covering overview controls, resources, subprocessors, FAQ, and update history.
July 22, 2026
Published draft Privacy Policy and Terms & Conditions for app linking and customer review pending final counsel approval.