Skip to main content
Axiom Codex pulls evidence directly from the systems your auditor needs to see — IdP, MDM, code repos, ticketing — and maps it to SOC 2, ISO 27001, and HIPAA controls automatically. Most controls fill themselves; you only assign humans to the ones that genuinely need a human.
1

Create your workspace

Sign up at app.axiomcodex.io. You’ll need an admin email on your company domain.
2

Pick your starting framework

On the welcome screen, select one or more:
  • SOC 2 Type I or II — see the SOC 2 guide
  • ISO 27001:2022 — see the ISO 27001 guide
  • HIPAA — Security Rule, Privacy Rule, or both
You can add frameworks later — start with one to keep the cognitive load low.
3

Connect evidence sources

Open Integrations and connect:
  • Identity — Google Workspace, Microsoft 365, Okta (auto-fills access reviews, MFA enforcement, deactivation logs)
  • MDM — Jamf, Kandji, Intune (auto-fills disk encryption, OS patching, screen lock)
  • Code host — GitHub, GitLab (auto-fills code review, branch protection, vulnerability scanning)
  • Ticketing — Jira, Linear (auto-fills change management, incident response)
  • Cloud — AWS, GCP, Azure (auto-fills logging, backup, network segmentation)
Most controls auto-fill within an hour of connecting.
4

Review the auto-evidence

Open Controls and filter by framework. Each control shows:
  • Status: Met, partial, missing, or N/A
  • Evidence: live snapshots from connected sources, with source + timestamp
  • Last verified: when Codex last re-pulled evidence
Click into any control to see the underlying data and manually mark exceptions.
5

Assign controls that need a human

Some controls (training records, vendor due diligence, BCP testing) can’t be auto-evidenced. Assign owners and set due dates from the Controls page. Codex sends reminders at 7d / 3d / 1d / overdue.
6

Generate audit-ready exports

When your auditor asks for evidence, Reports → Generate produces a PDF with every control, evidence source, and timestamp. CSV export is also available for auditor-portal upload.

What Codex doesn’t do

Codex is evidence collection and gap-finding, not policy authoring. We don’t ship boilerplate policies — too many of them are wrong for your business, and auditors are wise to copy-paste templates anyway. We integrate with Notion, Confluence, and Google Docs so you write policies where you already write everything else.

What auditors say

Auditors who’ve reviewed Codex evidence packages flag two things consistently:
  1. Timestamps are real — every evidence snapshot includes the API call time, not “we generated this last Tuesday”
  2. Source pointers — every claim has a “see exact API response here” link, which is what they actually need to validate

Need help?

Email support@axiomancer.io or open the in-app chat. For SOC 2 readiness assessments and audit prep, ask about our partner network.