Skip to content

Security and trust at Maximus

Maximus is built so that a security reviewer can finish their evaluation without a sales call. Customer data is encrypted in transit and at rest, access is controlled by SSO, SCIM and role-based permissions, and customer data is never used to train foundation models. The controls, their current status and the sub-processors behind them are listed on this page rather than summarised.

This page states the controls Maximus operates and the current status of each. Where a control or a figure has not been verified, it says so rather than rounding up. Anything marked TODO-SUBSTANTIATE is pending confirmation and is not a published commitment.

Supporting documents: the sub-processor list, the data processing addendum and the privacy policy.

Answers first

What a reviewer asks

The five questions a security reviewer asks, answered in the reviewer's own words before anything else on this page.

Where is my data?
Maximus customer data is stored in the United States, the European Union or India, and the region is selected when your workspace is provisioned. Data is encrypted in transit and at rest, and customer PII is encrypted at the field level. Backup and disaster-recovery targets are stated under data protection below.
Who can see it?
Access to a Maximus workspace is controlled by SAML 2.0 single sign-on, SCIM provisioning and de-provisioning, role-based access control with field-level permissions, and configurable IP allowlisting and session timeouts. Maximus staff access follows least privilege, and every mutation is written to an audit log with the actor, the action, the timestamp and the result.
Is it training a model?
No. Maximus customer data is never used to train foundation models, and that commitment is contractual and sits in the data processing addendum. The sub-processors that process customer data, including the model providers, are listed on the sub-processor page with 30 days' notice before any change to that list.
What happens if you're breached?
Maximus operates an incident response process with a written root-cause analysis commitment, a critical patch target, and a vulnerability disclosure programme. Audit logs are immutable and exportable to Splunk or Datadog, so the record of what happened is available to you independently of Maximus. Response timelines and notification commitments are contractual and are being confirmed before launch.
Can I get my data out?
Yes. Retention is configurable per workspace and hard delete is available on request, and a documented erasure process removes a record and the derived records within 30 days. Agent actions are logged with their full input, output and reasoning trace and are exportable, so the audit history leaves with you.
Group 1

Certifications and attestations

Certifications and attestations
ItemStatusWhat that means
SOC 2 Type IIIn progress — not yet verifiedAudit status is being confirmed against the current report. The report is made available under NDA on request.
ISO 27001In progress — not yet verifiedCertification programme. The certificate is not held yet, so no certificate number is published here.
Penetration testingIn progress — not yet verifiedIndependent test cadence is being confirmed. A summary letter is available on request.
GDPR and India DPDPIn progress — not yet verifiedConsent is captured with its source and timestamp and is unchecked by default. The data processing addendum is being reviewed by counsel.

How to read the certification status

Maximus publishes no certification badge until the certificate or the report is in hand and the mark is licensed for use.

A certification is either held or it is not. Maximus states the current position instead of implying that a programme in progress is complete, and it displays no compliance logo for a certification it does not hold, because a badge is a claim rendered as a graphic. To request the SOC 2 report or a penetration-test summary letter under NDA, use the request form below.

Group 2

Data protection

Data protection
ItemStatusWhat that means
TLS 1.3 in transitIn progress — not yet verifiedAll traffic to Maximus is served over TLS.
AES-256 encryption at restIn progress — not yet verifiedApplies to the primary datastore and to backups.
Field-level encryption for customer PIIIn progress — not yet verifiedApplied to customer identifiers rather than to the whole record.
Data residency: United States, European Union or IndiaIn progress — not yet verifiedSelected at provisioning. Confirm which regions are live before this is stated as available.
Configurable retention and hard deleteIn progress — not yet verifiedUnconverted leads are purged after 24 months and cart records after 12 months; workspace retention is configurable.
Encrypted, tested backupsIn progress — not yet verifiedRecovery point and recovery time objectives: TODO-SUBSTANTIATE.
Group 3

Access control

Access control
ItemStatusWhat that means
SAML 2.0 single sign-onIn progress — not yet verifiedOkta, Microsoft Entra ID, Google Workspace and JumpCloud.
SCIM provisioning and de-provisioningIn progress — not yet verifiedJoiner, mover and leaver events are reflected from your identity provider.
Role-based access control with field-level permissionsIn progress — not yet verifiedCustom roles are definable per workspace, down to individual fields.
Least-privilege integrationsIn progress — not yet verifiedRead-only OAuth scopes by default; write scopes are opted into per action class.
IP allowlisting, session timeout and MFAIn progress — not yet verifiedEnforceable per workspace rather than per user.
Immutable audit logIn progress — not yet verifiedEvery mutation records actor, action, timestamp and result, with no PII payload.
Group 4

AI and data usage

AI and data usage
ItemStatusWhat that means
Customer data is never used to train foundation modelsIn progress — not yet verifiedContractual, and stated in the data processing addendum rather than only on this page.
Sub-processor list for model providersIn progress — not yet verifiedPublished on the sub-processor page with 30 days' notice before any change. Names: TODO-SUBSTANTIATE.
Agent actions logged with input, output and reasoning traceIn progress — not yet verifiedExportable, so an action can be reconstructed after the fact.
Human-in-the-loop approval gates per action classIn progress — not yet verifiedYou decide which actions reach a customer on their own and which wait for a person.
No customer data retained by model providers beyond the requestIn progress — not yet verifiedDepends on the provider contract; see the sub-processor page.

Is my customer data used to train AI models?

Customer data is not training data. The agents read your stack to decide when to act; they do not learn from your accounts.

No. Maximus customer data is never used to train foundation models, and the commitment is contractual and recorded in the data processing addendum. Model providers are listed as sub-processors with their purpose, the data they process and their region, and the sub-processor page carries the notice period Maximus gives before that list changes.

Agent actions are visible rather than opaque. Every run records its trigger, the signals it read, the actions it took and whether a person approved it, and the trace is exportable. Approval gates are configurable per action class, so an action that reaches a customer can be made to require a human first.

The sub-processor names, regions and data categories are marked TODO-SUBSTANTIATE until the executed agreements are confirmed. See the sub-processor list.

Group 5

Operational security

Operational security
ItemStatusWhat that means
Uptime SLA with a public status pageIn progress — not yet verifiedSLA percentage: TODO-SUBSTANTIATE.
Audit logs exportable to Splunk or DatadogIn progress — not yet verifiedImmutable once written.
Critical patch SLAIn progress — not yet verifiedPatch target: TODO-SUBSTANTIATE.
Incident response with root-cause analysisIn progress — not yet verifiedNotification commitments are contractual and are being confirmed.
Vulnerability disclosure programmeIn progress — not yet verifiedReports are triaged and acknowledged; coordinated disclosure is preferred.
Request

Request the SOC 2 report

The SOC 2 report and the penetration-test summary letter are sent under NDA. Tell us where to send it and who it is for.

Maximus uses this address to send the report and to answer the request. It is not added to a marketing list unless the box above is ticked.

Forward this

Security overview

One page covering the same controls as this page, written to be forwarded to a CISO or a procurement reviewer.

The security overview is a one-page summary of the controls on this page: encryption, residency, access control, AI data usage and operational security. Enter a work email to download it.

The overview is sent to the address you give above.

Questions

Questions a security reviewer asks Maximus

Request it through the form on this page. Maximus sends the report under NDA, and the request is recorded as a security lead so it reaches the team directly rather than entering a general sales queue.

No. Maximus never uses customer data to train foundation models, and the commitment is written into the data processing addendum rather than resting on this page alone.

Maximus provisions workspaces in the United States, the European Union or India, and the region is chosen at provisioning time rather than after the fact.

Maximus publishes its sub-processors with their purpose, the data they process and their region, and gives 30 days' notice before a change to that list.

Yes. Agent runs and audit logs are exportable, retention is configurable per workspace, and a documented erasure process removes a record and its derived records within 30 days.

More answers in the FAQ hub and in the sub-processor list.

Next step

Send this page to your reviewer.

If the review needs a document, a control description or a call with the team, the request form above reaches them directly. Pricing and the full feature list are public, so nothing here waits on a sales conversation.

Figures marked TODO-SUBSTANTIATE are pending confirmation and are not published commitments.