Privacy Policy

Last Updated: July 21st, 2026

Privacy Policy

Last updated: 07/21/2026

Axiom Specialty [, Inc.] ("Axiom," "we," "us," or "our") provides insurance products and related risk‑management software for emerging‑technology risks. This Privacy Policy explains how we collect, use, disclose, and safeguard information across our websites, our insurance services, and our software products - including RAPTOR, our AI‑governance monitoring application.

By using our websites, services, or software, you agree to this Policy. If you do not agree, please do not use them.

1. Who this Policy covers

This Policy applies to:

  • Visitors to our websites (including axiomspecialty.com and govern.axiomspecialty.com);

  • Applicants for, and holders of, insurance we underwrite or administer;

  • Organizations and their authorized users who use RAPTOR (whether provided with a policy or purchased standalone).

Insurance we provide is separately governed by the terms of the applicable insurance policy; where this Policy and a policy conflict as to insurance data, the policy controls.

2. Information we collect

a. Information you provide. Business and contact details, insurance application and underwriting information, account credentials, billing information (processed by our payment provider), and communications you send us.

b. Information collected automatically. Device, log, and usage data, and cookies or similar technologies on our websites.

c. Connected‑workspace data (RAPTOR). When an authorized administrator connects your organization's Google Workspace or Microsoft 365 to RAPTOR, we access certain administrative data read‑only to assess your AI‑governance posture. See Section 4 for the full, product‑specific disclosure.

We do not intentionally collect special categories of personal data, and RAPTOR is not designed to ingest message content, files, or personal communications.

3. How we use information

We use information to: provide and administer insurance and risk‑management services; underwrite, price, and monitor risk (including at renewal); provide, secure, and improve our software; process billing; respond to support requests; comply with legal, regulatory, and reinsurance obligations; and detect and prevent fraud, abuse, and security incidents.

4. RAPTOR - connected Google Workspace & Microsoft 365 data

When your administrator connects a workspace, RAPTOR accesses the following read‑only. We never modify, delete, send, or move anything in your workspace.

From Google Workspace (via the Google Admin SDK and Chrome Management APIs):

  • Directory (users) — read‑only: your organization's user list and multi‑factor‑authentication enrollment status, to measure monitored headcount and account‑security posture.

  • Admin audit reports — read‑only: administrative activity/audit logs, to detect unsanctioned ("shadow") AI‑tool authorizations, generative‑AI usage, external data‑sharing exposure, and after‑hours activity.

  • Chrome app inventory — read‑only: details of applications/extensions installed on browsers and devices your organization manages, to inventory AI browser extensions.

From Microsoft 365 (via Microsoft Graph and the Office 365 Management Activity API): equivalent read‑only directory, audit/activity, security‑posture, and Copilot‑usage signals, used for the same purposes.

How we use this data. Solely to compute AI‑governance risk metrics that we present to your organization and use for underwriting and continuous policy monitoring. We aggregate this data into governance signals; we do not build advertising profiles from it.

Limited use. RAPTOR's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not: sell this data; use or transfer it for advertising; allow humans to read it, except (i) with your consent, (ii) as necessary for security or to comply with law, or (iii) where the data is aggregated and used for internal operations in line with this Policy.

Storage & retention. We store aggregated governance metrics and the minimal raw signals needed to produce them, encrypted in transit and at rest. See Section 7.

Disconnecting & deletion. An administrator may disconnect a workspace at any time from RAPTOR's settings, which stops further data collection. To request deletion of collected data, contact us at privacy@axiomspecialty.com; we will delete it within a commercially reasonable period, except where retention is required by law or for an active insurance policy or claim.

5. How we share information

We share information only with: service providers who process data on our behalf (e.g., cloud hosting, payment processing) under confidentiality obligations; insurance counterparties where applicable (e.g., carriers, reinsurers, and regulators) to provide and administer coverage; legal and safety recipients where required by law or to protect rights and safety; and acquirers in a merger, financing, or sale of assets. We do not sell your personal information, and we do not share connected‑workspace data for advertising.

6. Your choices and rights

Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object or withdraw consent. To exercise these, contact privacy@axiomspecialty.com. We will respond as required by applicable law. You can also disconnect any connected workspace at any time.

7. Data retention

We retain information for as long as needed to provide our services and for legitimate business and legal purposes. Connected‑workspace governance data is retained for 12 months, after which it is deleted or de‑identified, unless a longer period is required by law or for an active claim.

8. Security

We use administrative, technical, and physical safeguards including encryption in transit and at rest, access controls, and least‑privilege practices. No method of transmission or storage is fully secure; we cannot guarantee absolute security.

9. International data transfers

We may process information in the United States and other countries. Where required, we use appropriate safeguards for cross‑border transfers.

10. Children

Our services are for organizations and are not directed to children under 16, and we do not knowingly collect their personal information.

11. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date; material changes will be communicated as required by law.

12. Contact us

Axiom Specialty [, Inc.]
246 E 46th St, #3E, NY, NY, 10017
Email: privacy@axiomspecialty.com

Privacy Policy

Last updated: 07/21/2026

Axiom Specialty [, Inc.] ("Axiom," "we," "us," or "our") provides insurance products and related risk‑management software for emerging‑technology risks. This Privacy Policy explains how we collect, use, disclose, and safeguard information across our websites, our insurance services, and our software products - including RAPTOR, our AI‑governance monitoring application.

By using our websites, services, or software, you agree to this Policy. If you do not agree, please do not use them.

1. Who this Policy covers

This Policy applies to:

  • Visitors to our websites (including axiomspecialty.com and govern.axiomspecialty.com);

  • Applicants for, and holders of, insurance we underwrite or administer;

  • Organizations and their authorized users who use RAPTOR (whether provided with a policy or purchased standalone).

Insurance we provide is separately governed by the terms of the applicable insurance policy; where this Policy and a policy conflict as to insurance data, the policy controls.

2. Information we collect

a. Information you provide. Business and contact details, insurance application and underwriting information, account credentials, billing information (processed by our payment provider), and communications you send us.

b. Information collected automatically. Device, log, and usage data, and cookies or similar technologies on our websites.

c. Connected‑workspace data (RAPTOR). When an authorized administrator connects your organization's Google Workspace or Microsoft 365 to RAPTOR, we access certain administrative data read‑only to assess your AI‑governance posture. See Section 4 for the full, product‑specific disclosure.

We do not intentionally collect special categories of personal data, and RAPTOR is not designed to ingest message content, files, or personal communications.

3. How we use information

We use information to: provide and administer insurance and risk‑management services; underwrite, price, and monitor risk (including at renewal); provide, secure, and improve our software; process billing; respond to support requests; comply with legal, regulatory, and reinsurance obligations; and detect and prevent fraud, abuse, and security incidents.

4. RAPTOR - connected Google Workspace & Microsoft 365 data

When your administrator connects a workspace, RAPTOR accesses the following read‑only. We never modify, delete, send, or move anything in your workspace.

From Google Workspace (via the Google Admin SDK and Chrome Management APIs):

  • Directory (users) — read‑only: your organization's user list and multi‑factor‑authentication enrollment status, to measure monitored headcount and account‑security posture.

  • Admin audit reports — read‑only: administrative activity/audit logs, to detect unsanctioned ("shadow") AI‑tool authorizations, generative‑AI usage, external data‑sharing exposure, and after‑hours activity.

  • Chrome app inventory — read‑only: details of applications/extensions installed on browsers and devices your organization manages, to inventory AI browser extensions.

From Microsoft 365 (via Microsoft Graph and the Office 365 Management Activity API): equivalent read‑only directory, audit/activity, security‑posture, and Copilot‑usage signals, used for the same purposes.

How we use this data. Solely to compute AI‑governance risk metrics that we present to your organization and use for underwriting and continuous policy monitoring. We aggregate this data into governance signals; we do not build advertising profiles from it.

Limited use. RAPTOR's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not: sell this data; use or transfer it for advertising; allow humans to read it, except (i) with your consent, (ii) as necessary for security or to comply with law, or (iii) where the data is aggregated and used for internal operations in line with this Policy.

Storage & retention. We store aggregated governance metrics and the minimal raw signals needed to produce them, encrypted in transit and at rest. See Section 7.

Disconnecting & deletion. An administrator may disconnect a workspace at any time from RAPTOR's settings, which stops further data collection. To request deletion of collected data, contact us at privacy@axiomspecialty.com; we will delete it within a commercially reasonable period, except where retention is required by law or for an active insurance policy or claim.

5. How we share information

We share information only with: service providers who process data on our behalf (e.g., cloud hosting, payment processing) under confidentiality obligations; insurance counterparties where applicable (e.g., carriers, reinsurers, and regulators) to provide and administer coverage; legal and safety recipients where required by law or to protect rights and safety; and acquirers in a merger, financing, or sale of assets. We do not sell your personal information, and we do not share connected‑workspace data for advertising.

6. Your choices and rights

Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object or withdraw consent. To exercise these, contact privacy@axiomspecialty.com. We will respond as required by applicable law. You can also disconnect any connected workspace at any time.

7. Data retention

We retain information for as long as needed to provide our services and for legitimate business and legal purposes. Connected‑workspace governance data is retained for 12 months, after which it is deleted or de‑identified, unless a longer period is required by law or for an active claim.

8. Security

We use administrative, technical, and physical safeguards including encryption in transit and at rest, access controls, and least‑privilege practices. No method of transmission or storage is fully secure; we cannot guarantee absolute security.

9. International data transfers

We may process information in the United States and other countries. Where required, we use appropriate safeguards for cross‑border transfers.

10. Children

Our services are for organizations and are not directed to children under 16, and we do not knowingly collect their personal information.

11. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date; material changes will be communicated as required by law.

12. Contact us

Axiom Specialty [, Inc.]
246 E 46th St, #3E, NY, NY, 10017
Email: privacy@axiomspecialty.com