Security

Security belongs inside the architecture.

Our security model is based on explicit access boundaries, data minimization, operational visibility and disciplined software delivery.

Security practice areas

  • Identity & access

    Least privilege, strong authentication and environment separation are built into system boundaries.

  • Data protection

    Classification, encryption, retention and transfer requirements are treated as architectural constraints.

  • Secure delivery

    Code review, dependency control, secrets handling and deployment controls are part of the engineering lifecycle.

  • Observability

    Security-relevant events are designed to be visible, attributable and reviewable.

  • Resilience

    Backups, recovery, failure isolation and incident response are considered before production launch.

  • AI controls

    Prompt injection, data leakage, authorization boundaries and model behavior are evaluated as specific system risks.

No certifications are claimed on this site unless and until they are independently obtained and verifiable.

Vulnerability disclosure

Reporting a vulnerability.

If you believe you have found a security vulnerability affecting this website or Araxion Systems, please report it privately by email.

Security contact

security@gk-f1.win

Reports are accepted in English. The same contact details are published in machine-readable form, following the security.txt convention.

/.well-known/security.txt

A useful report

  • The affected URL, component or system.
  • A description of the issue and its potential impact.
  • The steps needed to reproduce it.
  • Please do not access or change data that is not yours, and do not degrade service availability while testing.

General questions about our security practice can be sent to contact@gk-f1.win.

Trust starts with verifiable controls.

Security inquiries