Trust Center
Security & multi-tenant controls
Axix Visitor is built as multi-tenant SaaS with gate access controls, QR expiry, and audit snapshots.
Tenant isolation
Har company ka data user_email / tenant scope se alag.
ACTIVE / BLOCKED
Blocked visitors gate pe effectively use nahi kar sakte.
QR expiry
Time-bound digital pass.
Face index
Enrolled photos → FAISS embeddings.
Device visibility
Door Access monitoring.
Role separation
Web admin vs Mobile App Login vs Host email actions.
Snapshots
Gate check-in images for audit trail.

Trust Center
Trust Center summarizes security and multi-tenant controls from section twelve of the product guide. Tenant isolation keeps each company’s visitor data in its own scope. Gate controls include ACTIVE and BLOCKED status, QR expiry, face embeddings, and check-in snapshots. Roles and devices cover web versus mobile versus host email actions plus Door Access visibility. Deploy posture highlights Docker Compose and cloud SaaS readiness with PostgreSQL and Redis jobs. Read this when security reviewers want controls without a full architecture workshop.

Tenant isolation
Each company works inside a scoped tenant so visitor lists never cross. Gate events, host emails, and exports inherit the same boundary. Shared infrastructure does not imply shared data visibility. Isolation is enforceable design, not a courtesy filter in the UI alone. Security questionnaires should start with this guarantee. Tenant isolation is the foundation claim of the Trust Center.

Gate controls
ACTIVE and BLOCKED status decide allow versus deny at verify time. QR expiry stops stale passes from unlocking entrances. Face embeddings support recognition while snapshots preserve arrival evidence. Controls are visible to operators through enrollment and kiosk outcomes. Combined, they create layered defense for visitor entry. Gate controls turn policy into something the camera lane can enforce.

Roles & devices
Web admins, mobile field users, and host email actors have different powers. Separation limits blast radius and clarifies audit ownership. Door Access shows which gate devices are online or offline for ops readiness. Role and device clarity helps IT answer who could change what. Trust reviews often care as much about people paths as crypto. Roles and devices make the human side of security explicit.

Deploy posture
Docker Compose packaging supports repeatable production and cloud SaaS styles. PostgreSQL stores tenant data with the durability ops teams expect. Redis-backed jobs support overdue checks and related scheduled work. Nginx and standard web tiers fit common enterprise edge patterns. Deploy posture is about operable security, not only feature screenshots. Reviewers can map controls to running services with less guesswork.
Trust controls evaluators verify
Security reviewers look for isolation, gate authority, and deploy clarity.
Company-scoped data
Visitor photos, hosts, and reports must never leak across tenants.
Gate identity controls
ACTIVE/BLOCKED, QR expiry, face embeddings, and snapshots form the entry trust model.
Role separation
Web, mobile, and host email actions should match least-privilege operational needs.
Operational trust signals
Trust is also how the system behaves on a busy Monday morning.
Device visibility
Online/offline door status prevents silent failures at the physical perimeter.
Overdue transparency
Visitor Alert keeps late guests visible to security, not only in a host inbox.
Exportable evidence
PDF/CSV packs give auditors a reproducible record of site visits.
Deploy posture questions
Ask these before approving production.
Where does data reside?
Confirm Docker/cloud posture and database ownership for your compliance model.
Who can change BLOCKED?
Document which roles may alter visitor status after an incident.
Next step
See this flow in a live demo
Transform your front desk with secure visitor management.
Register guests, check them in with face or QR, alert hosts by email, and export complete visitor reports.
