You have scripts running on
dozens of servers. Are they safe?

Axiom replaces SSH + crontab sprawl with a pull-model orchestrator — every node mTLS-verified, every script Ed25519-signed before it runs.

Nodes Jobs Audit log
node-alpha
python bash
CPU 23%
node-beta
python powershell
CPU 61%
node-gamma
offline · 4h ago

Real dashboard — no mock data in prod

The dashboard your operators will actually use

Real screenshots from a live Axiom deployment — no mock data.

Axiom dashboard — live node metrics and job queue summary

Dashboard — live overview

Nodes page — enrolled nodes with ONLINE status and capabilities

Nodes — mTLS-enrolled fleet

Jobs dispatch interface with signed script execution history

Jobs — signed script execution

Audit log showing security events and job execution trail

Audit log — immutable trail

SSH + crontab doesn't scale

🔑

SSH key sprawl

Keys on every server, revocation is manual, and you can't prove who ran what.

📋

No audit trail

Scripts ran. You think. Cron has no log of who triggered what or whether it succeeded.

⚠️

Unsigned execution

Any script that lands on a node runs. There's no verification it hasn't been tampered with.

Security that satisfies your infosec team

🔏

Cryptographic audit trail

Every job execution is Ed25519-signed before it runs and logged with a full audit record. You know who ran what — and you can prove it.

🛡️

Least-privilege RBAC

Three built-in roles: admin, operator, viewer. No shared accounts. Permissions are scoped and auditable from day one.

🏢

Air-gapped deployment

Fully self-hosted. No telemetry, no cloud dependency, no data leaves your network. Runs on your infrastructure, under your control.

🔐

Certificate-based node identity

Each node holds a unique mTLS client certificate. Revocation is cryptographic — not a password reset.

Community & Enterprise

Community Edition

Free — Apache 2.0
  • Job execution (Python, Bash, PowerShell)
  • Node management with mTLS enrollment
  • Ed25519 job signing + pre-execution verification
  • Cron scheduling with capability targeting

Enterprise Edition

Early access

Built with early design partners — shaped by real enterprise deployments.

Everything in CE, plus:

  • RBAC with three roles (admin, operator, viewer)
  • Audit log for all security-relevant actions
  • Foundry image builder for custom node environments
  • Execution history with cryptographic attestation
  • Per-node resource limits (memory & CPU)
  • Node enrollment limits and fleet governance
  • SAML 2.0 / OIDC SSO integration
Interested in Enterprise? Get in touch →

Cold-start in under 30 minutes

Full stack, no cloud account required.

docker compose -f compose.cold-start.yaml up -d
Read the install guide →

Get early access

We're working with design partners now. Tell us about your environment.

Get early access →