Axyom Agent · Operate
An agent that only talks about your company.
The modules produce signal: your exposed surface, your leaked credentials, the status of your machines, your framework controls. Axyom Agent is where you ask about and act on all of that, in the portal or in your Slack, without opening one more console and without translating jargon.
The file the agent talks about starts with the scan of your domain.
What it is
The platform's interface.
Axyom Agent is the platform's interface. Axyom's modules are sensors: each looks at one surface and produces findings. The agent adds no surface. It turns what the others produce into something you can decide and act on, in the portal and in a private Slack channel with your team.
The problem it solves appears in companies of 10 to 250 people that already have security tools. The signals arrive from different places, in technical jargon and in no order, and nobody in-house has time to read them in full or to turn them into work. The agent closes that gap every day, with the answer and the work already prepared.
The cost of not having it is paid in time and deadlines. A tool that requires logging into a panel to find something out ends up with nobody logging in, and the customer's security questionnaire, the board report or the remediation plan get written by hand, from scratch every time, with the evidence scattered across tabs.
2
channels where the agent lives
4
plans that include it
0
changes without your approval
- What it is
- The place where your team asks and decides about all the signal the modules produce, in the portal and in Slack, without opening one more console.
- Who it is for
- Companies of 10 to 250 employees where nobody has the whole day to watch security dashboards. The team asks in its own language and gets the answer with the evidence linked.
- Where it's included
- In every plan, to ask questions and prioritize. Entry-level access already allows conversation with usage limits. Base widens the context with the available integrations.
- What we need
- Your domain for the first scan, which fills the file. For Slack, connect the workspace with the corresponding permissions and access and complete the installation of the private channel.
- Cadence
- It answers when you ask about the available file. The information from each source keeps its last sync; usage limits depend on the plan.
What it answers questions about
Everything there is in your file.
Everything the modules produce goes into the same file, and the agent answers questions about it with the record linked.
- External Scanner
- What the last pass found, what to close first and which action it recommends to fix it.
- Continuous Compliance
- Which control is failing, which finding contradicts it and which document is still to be uploaded.
- Leaked credentials
- Which credentials of your domain are exposed, since when they have been watched and what severity they carry.
- Machine status
- Which machines are up to date, which have open detections and what is still to be deployed.
- AI Risk
- Which AI applications hold permissions over your data and with what scope.
- Customer questionnaires
- Which questions already have an answer with the evidence there is and which ones call for a business decision.
- Score and insurability
- What moves your CyberScore, which findings and controls are part of the available assessment.
- Security Advisor
- When the decision calls for judgment, the person steps into the same thread and signs the minutes.
The agent answers questions about what is connected. Each integration is shown with its last sync, and what is not integrated appears as a gap in the file.
Where its figures come from
The agent does not answer from memory.
Every answer starts by querying the file with read-only tools, and the count it gives is the one the portal shows.
Reading
Your whole file, read-only
Open findings, status per framework, integrations with their last sync, recent scans, documented exceptions, playbook and effort in minutes, closure rate, domains and subdomains. If a system is not connected, the agent says so instead of assuming its status.
Approval
It prepares and you approve
It explains the fix and can update the tracking of actions or findings and add notes, with your confirmation. Execution on your systems is done by your team or your provider, and every change stays in the auditable log with who did it and when.
Channels
In the portal and in Slack
In the portal it answers next to the file and every answer links to the record, the action and the evidence. In Slack it lives in a private channel with your team, where the work is discussed and decided without opening another screen.
What it does on a normal day
It translates what a finding means for your business, without the CVE jargon. It prioritizes where to start, with each finding's score, the estimated effort and the effect closing it has on your overall score and on your insurability. It prepares the draft answer to a customer questionnaire with the evidence linked, the board report and the remediation plan with owners. And it acts when you approve: it explains the fix, updates the tracking and adds notes with your confirmation.
Sample Slack conversation · Sample data
- You
- A customer just sent us their security questionnaire. They want it by Friday.
- Axyom Agent
- We can prepare the answers with the evidence available in your file: email, certificates, access and the connected systems. I will set aside the questions that need additional information or a business decision.
- You
- And the ones that need a decision?
- Axyom Agent
- We'll leave them flagged in the draft to review with the person in charge. The technical answers must keep the source and the date of their evidence.
What it leaves prepared
Three things you can show or execute.
The draft answer
The answer to a customer's security questionnaire, with the evidence linked question by question and the ones that call for a business decision flagged separately so the decision-maker sees them.
The plan with owners
Where to start and why, with each finding's score, the estimated effort and the effect of each closure on your overall score. You can review the existing actions and confirm the tracking changes Axyom supports.
The report
What the current posture means for the business, without CVE jargon, with the score history and what changes if the backlog gets closed. It sits ready, waiting for you to use it.
Where it fits in the platform
The agent lives outside the three layers.
In the menu, the agent appears outside the prevention, detection and transfer layers, next to Security Advisor. Prevention, detection and transfer group the modules that produce signal; the agent and the person are the way that signal reaches your team and turns into work. Every answer from the agent links to the record of the module that produced it, to the open action and to the evidence behind it.
Security Advisor
The human judgment: on escalation in Pro and with a named person in Max, in the same thread.
Learn moreExternal Scanner
The sensor that fills the file on day one, with your public surface and your score.
Learn moreContinuous Compliance
The status per framework with its evidence, which is where the compliance answers come from.
Learn moreLimits
What this agent does not do.
Check the scope before turning on the module and coordinate with your team the actions that fall to them.
It executes no changes without approval
It prepares, drafts and leaves things ready. Nothing goes out or gets touched until someone on your team approves it, and every change is recorded.
It does not go into your systems to fix things
Execution is done by your team or your IT provider, with the step-by-step playbook in front of them and the evidence back in the portal.
It does not answer questions about what is not connected
If a system is not integrated, the agent does not see its status and says so. It does not fill gaps with reasonable assumptions.
It does not sign off on judgment calls
Accepting a risk, negotiating a clause or classifying an incident are a person's decisions, and they are escalated to the Security Advisor.
It is not a general-purpose assistant
It only talks about your company's security and what is in your file. For everything else you already have other tools.
It does not replace the system's alert
Critical items still arrive through their alert channels. In the agent they get understood and decided, with what has already been done and what remains.
It produces no new signal
It looks at no surface on its own. It answers questions about what the modules produce, and what they do not cover it does not cover either.
It only lives in the portal and in Slack
Those are the two channels where you can talk to it today. Other messaging clients are not available and we do not promise them until they are.
Plans
The agent comes with every plan.
The agent comes with the platform and is not sold on its own. Entry-level access includes conversation with limits. From Base the context widens through integrations and from Pro human support is added.
Free
To see your real risk before deciding anything.
No cost · No card.
Everything to get looking:
- Continuous scan External surface, 24/7
- Posture and risk map Real-time CyberScore
- Leaked credentials Counted, no detail
Base
For companies that want the whole platform without a security team of their own.
Self-serve · No commitment.
Everything in Free, plus:
- Integrations Microsoft 365, Google Workspace and cloud
- AI risk Apps with permissions over your data
- Prioritized backlog Monthly remediation
- 1 domain Continuously scanned
Pro
For teams that need every sensor active and an expert behind it.
Advisor on escalation · No commitment.
Everything in Base, plus:
- Security advisor On escalation, with SLA
- Threat Intelligence Exposed credentials, under watch
- Recurring pentesting Authenticated, report reviewed by Axyom
- MDR 24/7 Up to 20 managed devices
- Up to 5 domains All continuously scanned
Max
For high exposure or compliance demands.
Dedicated advisor · No commitment.
Everything in Pro, plus:
- Dedicated security advisor A fixed person, monthly session
- Priority response Incidents
- Compliance by framework Downloadable evidence and attestation
- Audit support Customer questionnaires and due diligence
FAQs.
How is it different from a generic AI chat?
A generic chat knows about security in the abstract and does not know your company. Axyom Agent only talks about your file: it checks your findings, your status per framework, your integrations with their last sync, your scans and your exceptions before answering. If something is not connected, it says so.
Can it make changes to our systems?
It prepares the change and leaves it ready, and execution goes through an approval. It prepares an explanation or a draft and can update the tracking within Axyom after your confirmation. Nothing goes out or gets touched without someone on your team approving it.
Where do you talk to the agent?
In the portal, next to the file, and in a private Slack channel with your team. The conversation happens where you already work, and what it answers stays in view of whoever has to act rather than buried in an inbox.
Where do the figures it gives come from?
Every answer starts by querying the file with read-only tools. The agent is instructed to use the grouped count the portal shows and not the raw one per resource, so the number in the chat matches the one you see in the tabs.
Does the agent replace a person?
No, and the split is written down. The agent does the continuous work and answers at any hour. The decisions that call for judgment are signed off by the Security Advisor, the person who steps into the same thread: on escalation in Pro and with a dedicated advisor in Max.
Choose how to start.
On your own
Analyze your domain and start with your security posture. Then connect your systems and turn on the capabilities you need.
With our team
Tell us what you need to protect and which requirements you have. We will review the scope and the right plan with you.