Release scope: NIVOMAX Capstone (2025.2)
This statement describes the security-related capabilities and responsibilities associated with NIVOMAX Capstone. It applies to the NIVOMAX software platform and its applications. It does not describe the configuration of www.nivomax.com or establish the security of a particular customer installation.
1. Platform and application scope
NIVOMAX Capstone includes Syntaxis, Arkitect, Aerotrade, Axis and Horizon. The applications work through the shared NIVOMAX identity layer, with access governed by the user's organization, role and applicable entitlements.
Available capabilities depend on the applications, delivery editions and extension modules licensed for the installation, together with its configuration.
2. Identity and authentication
NIVOMAX supports integration with enterprise identity providers through SAML 2.0, OAuth 2.0 and OpenID Connect. Supported capabilities vary by protocol, identity provider and configuration.
Axis provides administration and system records for organizations, users, roles, data licenses and entitlements. Other NIVOMAX applications authenticate through the same NIVOMAX identity layer.
The selected identity provider and deployment configuration determine the sign-in experience and available authentication controls. Review those controls against the requirements of the installation.
3. Access controls and optional security extensions
Access to applications and technical publications depends on the user's permissions and entitlements. A deployment review should consider both administrative access and access to the technical data being delivered.
Separately licensed extension modules provide additional capabilities:
- Vigilance Sentinel provides authorization and access enforcement.
- Vigilance Watcher provides tamper-evident access and activity evidence.
- Vigilance Compliance supports entitlement recertification and reviewer decisions.
These are distinct modules. Their availability and behavior depend on the modules licensed and configured for the installation.
4. Data protection and delivery
The appropriate security configuration depends on the application, delivery edition, network environment and technical data involved.
A deployment review should identify the controls used for data in transit, stored publications, application configuration and access on end-user devices. It should also consider the licensed application's behavior when connectivity changes or technical data is used offline.
The public description of one application or delivery edition should not be treated as evidence that every edition has identical controls or operating requirements.
5. Deployment responsibilities
Software capabilities operate within an environment maintained by the Licensee and its service providers. A security review should cover the hosting infrastructure, identity provider, certificates, network access, operating systems, end-user devices, administrative permissions, backups and update procedures.
The responsibilities of Synaxiom, the Licensee and other providers are defined by the applicable agreements and deployment arrangements.
Customer integrations, local configuration and third-party components need to be included in the review of the actual installation.
6. Release-specific security information
Security questions should identify the relevant release, application versions, delivery editions and deployment configuration. Request the current information appropriate to that scope when assessing an installation or planning an upgrade.
This statement describes product capabilities and responsibilities. For vulnerability status, testing evidence or certification information, request the current release-specific material relevant to your assessment.
Product documentation, release information and applicable agreements should be used together when making security or procurement decisions.
7. Security questions and reports
Contact Synaxiom through Contact for security questions or to arrange an appropriate channel for reporting a suspected vulnerability.
Do not submit credentials, access tokens, confidential publications or sensitive diagnostic material through a general website form. Include only the information needed to identify the application and describe the concern until an appropriate reporting channel has been agreed.