Security Policy

Shared responsibility, tenant isolation, and security practices for the Maximus platform.

Security PolicyEffective 2026Last updated 2026

Transparency notice

These policies describe our standard practices and are published for transparency. If your organization has a signed agreement with us (for example, an MSA, order form, or data processing addendum), that contract controls where it conflicts with this summary. Please share these documents with your legal counsel before relying on them for compliance decisions.

Adversys Inc. ("Adversys") maintains this Security Policy to describe—in clear terms—how we protect the Maximus platform and the data processed through it. Security is shared: we secure the platform; Customer secures its accounts, authorizations, and use of integrations.

1. Security philosophy

Maximus is built for security-sensitive work. We combine defense-in-depth controls, tenant isolation, encryption, monitoring, and secure development practices. We review this policy regularly and update it when our practices or threat landscape change.

2. Shared responsibility

Platform (Adversys) • Host and patch application infrastructure • Enforce tenant isolation and access controls at the platform layer • Encrypt sensitive data in transit and at rest • Monitor for abuse and respond to incidents affecting the platform Customer organization • Manage users, roles, and offboarding • Maintain written authorization for security tests and scans • Protect account credentials and LLM API keys • Configure integrations securely and review vendor terms • Classify and handle findings and reports according to internal policy

3. Infrastructure and network security

• Cloud-hosted infrastructure with providers that maintain industry-standard certifications and audits • Network segmentation and firewalls to limit exposure • TLS for data in transit; AES-256 (or equivalent) for sensitive data at rest • Timely application of security patches and dependency updates • Continuous monitoring, logging, and alerting for anomalous activity

4. Identity and access management

• Authentication via industry-standard mechanisms (including SSO where configured) • Role-based access control (PM, SME, Admin, Platform Admin) within each tenant • Multi-factor authentication for privileged Adversys administrative access • Principle of least privilege and periodic access reviews • Audit logging of administrative and security-relevant actions

5. Tenant isolation

Each organization operates in a logically isolated tenant. Users, engagements, projects, credentials, LLM profiles, and integration settings are scoped to the active organization. We design and test controls intended to prevent cross-tenant data access.

6. Application security

• Secure development lifecycle practices, code review, and dependency management • Vulnerability scanning and penetration testing of the Maximus application • Separation between customer assessment workloads and platform control plane where architecturally appropriate • Responsible disclosure: report suspected vulnerabilities to MarkC@adversys.ai

7. Data protection and retention

• Encrypted backups and tested disaster recovery procedures • Data retention aligned with Customer agreements and administrator actions • Secure deletion procedures when tenants or data are decommissioned • Customer content is not used to train public third-party models via Adversys's AI features; LLM processing occurs through providers Customer selects

8. Incident response

We maintain an incident response program that includes detection, containment, investigation, remediation, and post-incident review. If we confirm a security incident that materially affects Customer personal data or tenant confidentiality, we will notify affected Customers without undue delay and provide information reasonably available to help them meet their obligations. Report security concerns to MarkC@adversys.ai.

9. Compliance

We design controls with reference to widely recognized frameworks and applicable regulations, which may include privacy laws such as the CCPA/CPRA for California residents. Specific compliance commitments (for example, SOC 2 reports or DPAs) are provided in Customer agreements when applicable—not all commitments apply to every deployment model.

10. Customer security obligations

To maintain a secure environment, Customer and its users should: • Use strong, unique passwords and enable MFA where offered • Limit Admin and Platform Admin roles to trusted personnel • Rotate integration and LLM credentials when personnel change • Report suspected compromise or policy violations promptly • Never share device enrollment tokens or API keys in unsecured channels

11. Policy updates

We post updates at /docs/legal/security with a revised "Last updated" date. Material changes may be communicated through in-product notice or email where appropriate. Adversys Inc. Security contact: MarkC@adversys.ai Address: 6977 Navajo Rd, San Diego, CA 92119-1503, United States These policies describe our standard practices and are published for transparency. If your organization has a signed agreement with us (for example, an MSA, order form, or data processing addendum), that contract controls where it conflicts with this summary. Please share these documents with your legal counsel before relying on them for compliance decisions.

Effective date: 2026. Last updated: 2026.

Related legal documents