Axsona← Back to website

Axsona · Pantas Software Sdn. Bhd.

Security Policy

Last updated 4 September 2026

This policy explains how Axsona approaches the security of its public website, systems and information handled in connection with prospective and agreed client engagements.


Scope and responsibility

Axsona is operated by Pantas Software Sdn. Bhd. ("Pantas", "Axsona", "we", "us" or "our"). This policy applies to the Axsona public website and to security practices used when evaluating or delivering Axsona services. A client agreement may include additional project-specific controls and will govern where it sets a different requirement.

Security programme

Our security approach is designed to assess risk, protect systems and information, detect suspicious activity, respond to incidents and improve controls over time. Measures are selected according to the nature of the system, the information involved and the risks reasonably identified.

Vulnerability management

Production environments are reviewed for known vulnerabilities and missing security updates. We monitor relevant security advisories and assess newly disclosed vulnerabilities so that appropriate remediation or mitigation can be prioritised according to risk.

Access and network protection

Access to systems and information is limited to authorised people and services with a business need. We use access controls, authentication measures, network protections and monitoring intended to reduce unauthorised access, brute-force activity and malicious traffic. Permissions and protective rules are reviewed and adjusted where appropriate.

Data protection

We use encryption to protect sensitive information in transit and may use encryption at rest, tokenisation, masking or other controls where appropriate to the information and service. Client materials should be transferred only through the method agreed for the engagement, not through general enquiry or scheduling channels.

Service providers

Axsona may use reputable hosting, communications, scheduling and other technology providers. We assess providers according to their role and the information they handle, restrict access where practicable and use contractual or organisational safeguards appropriate to the service.

Payment information

The Axsona public website does not request or directly process payment-card information. If payment functionality is introduced, payment details will be handled through an appropriately selected payment provider and this policy will be updated where necessary.

Incident response

Suspected security events are assessed and handled according to their nature and potential impact. Where a confirmed incident requires notification under applicable law or an agreement, we will notify affected parties or authorities within the required timeframe and provide available information appropriate to the circumstances.

Your responsibilities

Security is shared. You should protect your devices and accounts, use secure channels provided for a project, limit the personal or confidential information you submit, and tell us promptly if you suspect unauthorised access or another security issue. You must not test, scan or exploit Axsona systems without written permission.

Responsible reporting

If you believe you have found a security vulnerability affecting Axsona, email info@pantas.com with enough detail for us to investigate. Please act in good faith, avoid accessing or altering information that is not yours, do not disrupt services and allow a reasonable period for investigation before public disclosure.

Limitations and updates

No security programme can eliminate every risk, and this policy does not guarantee that incidents will never occur. We may update it as Axsona’s services, risks, technology or legal obligations change. The date above identifies the current version.

Project controls are scoped separately. Specific security, confidentiality, data-processing, retention and deletion requirements for a client engagement should be recorded in the applicable project agreement.