Early access

The first agentic ERP — early access openOur goal: the first agentic ERP system. Full ops suite live today (CRM through delivery). Public release targeted for September 1, 2026. After a year+ and thousands of hours of engineering.

Security & governance

Your data, protected by real controls.

You're trusting MaxorConnect with your pipeline, finances and operations. Here's exactly what protects them — the controls we actually ship, no unearned badges.

The controls

Defense in depth, on every plan.

Security isn't a tier you upgrade to. Every organization gets the same isolation, access control and audit trail from day one.

Org-level data isolation

Every query is scoped to your organization at the data layer. Multi-org users never see across boundaries — enforced, not just configured.

Attribute-based access control

Fine-grained ABAC — attribute policies, department scoping and data-sensitivity tiers — with role-based access (RBAC) underneath.

Step-up MFA on sensitive actions

High-risk actions demand a fresh authentication challenge. A stolen session isn't enough to move money or export data.

Full, exportable audit trail

Every action — human or AI agent — is logged with who, what and when. Access reviews and retention controls are built in.

Governed, grounded AI

Agents act through the same access policies as people, behind an approval queue. Every AI output is independence-checked before it reaches you.

Your data stays yours

Org-isolated, encrypted in transit and at rest, never sold, and never used to train third-party models.

Access control

Built for real organizations — not a role dropdown.

Full attribute-based access control so multi-entity and multi-department teams can run the business on one platform without oversharing.

Attribute policies
Grant access by role, team, region and custom attributes — policies that match how you actually work.
Departments & team scopes
Scope data and actions to the teams that own them. Multi-entity operators stay isolated by design.
Data-sensitivity tiers
Classify sensitive records and restrict who can see, export or change them.
Step-up MFA
High-risk actions demand a fresh authentication challenge — a stolen session is not enough.

Full ABAC on every plan — Team, Business and Enterprise. Plans differ by support, compliance ops and scale, not by locking access control.

Full security details
Shared responsibility

We secure the platform. You govern your org.

Security is a partnership. Here's the split — plain language, no fine print theater.

What Maxor runs

Infrastructure, encryption, org isolation, ABAC engine, audit storage, AI grounding firewall, and the controls listed on this page.

What your admins own

Who gets a seat, which attributes and departments apply, MFA policy for your users, what agents may do, and which integrations you authorize.

What agents must obey

The same policies and approval tiers as people. Agents use the governed API — not a shadow channel — and every action is auditable.

Standards & data handling

Built to the standards that matter.

We name what we actually ship — and we refuse certifications or badges we have not earned.

SOC 2 / ISO 27001 control standards
Engineered to those control frameworks. We say 'built to' — we don't claim a certification we don't hold.
Automatic data residency — US, EU or Canada
Sign in and your data is served from the replica in your region — the US, the EU or Canada — automatically, with no configuration or request. Encrypted in transit and at rest.
Privacy by design
GDPR, CCPA and Québec Law 25 aware. Cookieless analytics, org-scoped data, and a DPA on request.
FAQ

Security questions, answered honestly.

Are you SOC 2 certified?

We build to SOC 2 and ISO 27001 control standards. We do not claim a third-party certification we don't currently hold — when that changes, we'll say so here.

Is my data used to train AI models?

Never for third-party foundation models. Customer Data is not sold and is not used to train models we don't own. See the Privacy Policy.

Is ABAC only on Business?

Full ABAC is on every plan. Business adds packaging and ops support around governance at scale — not a lock on the control itself.

Can we get a DPA / security review?

Yes. A public Data Processing Addendum is at /legal/dpa; sub-processors, privacy and terms are under /legal. Contact us for early access, a countersigned DPA (SCCs where required), or a security review.

The first agentic ERP.
Request early access.

Join early access to the first ERP built for humans and agents on one governed platform. Full ops suite live today — public release targeted for September 1, 2026.

Security & access control