Security

Security and governance for public publishing and internal operations.

Axedro separates publishing, administration, and sensitive integrations with controls designed for enterprise environments.

Public publishing controlled through explicit contracts.
Clear separation between administrative routes and public endpoints.
Central governance for posts, pages, and pricing.

Controls that support the public surface

The public website inherits clear security and governance principles from the Axedro service ecosystem.

Publication guard

Public content only when it is truly published

The content-service public endpoints default to fail-closed behavior and do not expose drafts when schema or state are not safe.

Admin separation

Governance kept separate from the public surface

The admin-service controls posts, pages and pricing through explicit capabilities and audit-friendly flows.

Service boundaries

Sensitive internal integration stays token-protected

Flows such as email delivery remain authenticated service-to-service calls instead of being exposed to the browser.

Governance principles already applied

The focus is on verifiable controls in the current public contracts and operating flows.

Administrative capabilities separated for reading, editing and publishing content.

Canonical public routes separated from legacy aliases to reduce operational ambiguity.

Content sanitization and normalization before public publishing.

Logging and public contracts designed for troubleshooting without unnecessary exposure.

What this means in practice

Security here is operational: surface clarity, publishing governance and controlled internal integration.

Public website

Public content serves only what should be public

Blog, pages and pricing rely on explicit contracts and publication filters in content-service.

Admin CMS

Administration with capabilities and auditability

Publishing, editing and reviewing content depends on explicit administrative permissions in admin-service.

Lead flow

Commercial capture without exposing email infrastructure to the client

The website sends leads through a controlled public endpoint that relays the event internally to email-service.

Review security, governance, and deployment requirements with the Axedro team.

The conversation covers the public surface, administrative flow, and integration model.