Change alerts now run the moment a deploy finishes

Read the note

Priced per service, not per check

Write as many rules as you like. You pay for the services you protect, and nothing for the ones you have not got to yet.

Two months free on yearly

Solo

One project, one environment. Enough to see whether this is for you.

Free Free forever

Start free
  • Up to 5 rules
  • One project, one environment
  • Checks on pull requests
  • 30 days of history
  • Community support

Team

Every service protected, with checks in your deploy path.

$40 $33 per service, per month

Start 14-day trial
  • Unlimited rules
  • Every project and environment
  • Checks before every deploy
  • Change alerts every 15 minutes
  • Coverage report and weekly summary
  • Alerts to Slack and PagerDuty
  • 2 years of history

Enterprise

For teams that answer to auditors as well as an on-call rota.

Talk to us Talk to us

Contact sales
  • Everything in Team
  • 7 years of history
  • Run the checker on your own hardware
  • SAML, SCIM and audit logs
  • Overrides that need two people
  • A named engineer and a 99.95% SLA

How teams do this today

Three ways to solve the same problem, and where each one stops.

Capability Axiom Cloud policy tools A doc nobody reads
Rules live with your code Central repo
Stops a deploy
Catches hand-made changes
Tells you what is not protected
Keeps a history for audits Logs only
Runs on your laptop
Time to your first rule Minutes Weeks An afternoon

Questions we get asked

What counts as a service?

Anything with its own deploy. If two things ship together from one pipeline, they count as one. We would rather undercount than argue about it, so the invoice lists what we counted and you can merge rows.

Does Axiom get access to our cloud?

No. The checker runs inside your own pipeline and reads what is about to change, right there. What leaves your network is the result — the rule name, whether it passed, and whichever service names you choose to include.

What if a rule turns out to be wrong?

Give the rule a grace period and it will report without stopping anything until the date passes. Overrides are one command, always written down, and always sent to the owner.

Can we try it before we buy it?

The Solo plan is free forever and runs the same checker. Most teams write one rule, point it at something they already deploy, and know within an hour whether this is worth paying for.

Do we have to drop our current tools?

Not on day one. Axiom reads the same changes, so teams usually run both until the coverage report says every rule has moved across.

How do we prove a check really ran?

Every check is signed. Exports carry the key alongside them, so an auditor can verify the history themselves without an account and without asking us.

Free until it earns its place

One project, five rules, no card. Move up when you need to.