Security and trust at Maximus
Maximus is built so that a security reviewer can finish their evaluation without a sales call. Customer data is encrypted in transit and at rest, access is controlled by SSO, SCIM and role-based permissions, and customer data is never used to train foundation models. The controls, their current status and the sub-processors behind them are listed on this page rather than summarised.
This page states the controls Maximus operates and the current status of each. Where a control or a figure has not been verified, it says so rather than rounding up. Anything marked TODO-SUBSTANTIATE is pending confirmation and is not a published commitment.
Supporting documents: the sub-processor list, the data processing addendum and the privacy policy.
What a reviewer asks
The five questions a security reviewer asks, answered in the reviewer's own words before anything else on this page.
- Where is my data?
- Maximus customer data is stored in the United States, the European Union or India, and the region is selected when your workspace is provisioned. Data is encrypted in transit and at rest, and customer PII is encrypted at the field level. Backup and disaster-recovery targets are stated under data protection below.
- Who can see it?
- Access to a Maximus workspace is controlled by SAML 2.0 single sign-on, SCIM provisioning and de-provisioning, role-based access control with field-level permissions, and configurable IP allowlisting and session timeouts. Maximus staff access follows least privilege, and every mutation is written to an audit log with the actor, the action, the timestamp and the result.
- Is it training a model?
- No. Maximus customer data is never used to train foundation models, and that commitment is contractual and sits in the data processing addendum. The sub-processors that process customer data, including the model providers, are listed on the sub-processor page with 30 days' notice before any change to that list.
- What happens if you're breached?
- Maximus operates an incident response process with a written root-cause analysis commitment, a critical patch target, and a vulnerability disclosure programme. Audit logs are immutable and exportable to Splunk or Datadog, so the record of what happened is available to you independently of Maximus. Response timelines and notification commitments are contractual and are being confirmed before launch.
- Can I get my data out?
- Yes. Retention is configurable per workspace and hard delete is available on request, and a documented erasure process removes a record and the derived records within 30 days. Agent actions are logged with their full input, output and reasoning trace and are exportable, so the audit history leaves with you.
Certifications and attestations
| Item | Status | What that means |
|---|---|---|
| SOC 2 Type II | In progress — not yet verified | Audit status is being confirmed against the current report. The report is made available under NDA on request. |
| ISO 27001 | In progress — not yet verified | Certification programme. The certificate is not held yet, so no certificate number is published here. |
| Penetration testing | In progress — not yet verified | Independent test cadence is being confirmed. A summary letter is available on request. |
| GDPR and India DPDP | In progress — not yet verified | Consent is captured with its source and timestamp and is unchecked by default. The data processing addendum is being reviewed by counsel. |
How to read the certification status
Maximus publishes no certification badge until the certificate or the report is in hand and the mark is licensed for use.
A certification is either held or it is not. Maximus states the current position instead of implying that a programme in progress is complete, and it displays no compliance logo for a certification it does not hold, because a badge is a claim rendered as a graphic. To request the SOC 2 report or a penetration-test summary letter under NDA, use the request form below.
Data protection
| Item | Status | What that means |
|---|---|---|
| TLS 1.3 in transit | In progress — not yet verified | All traffic to Maximus is served over TLS. |
| AES-256 encryption at rest | In progress — not yet verified | Applies to the primary datastore and to backups. |
| Field-level encryption for customer PII | In progress — not yet verified | Applied to customer identifiers rather than to the whole record. |
| Data residency: United States, European Union or India | In progress — not yet verified | Selected at provisioning. Confirm which regions are live before this is stated as available. |
| Configurable retention and hard delete | In progress — not yet verified | Unconverted leads are purged after 24 months and cart records after 12 months; workspace retention is configurable. |
| Encrypted, tested backups | In progress — not yet verified | Recovery point and recovery time objectives: TODO-SUBSTANTIATE. |
Access control
| Item | Status | What that means |
|---|---|---|
| SAML 2.0 single sign-on | In progress — not yet verified | Okta, Microsoft Entra ID, Google Workspace and JumpCloud. |
| SCIM provisioning and de-provisioning | In progress — not yet verified | Joiner, mover and leaver events are reflected from your identity provider. |
| Role-based access control with field-level permissions | In progress — not yet verified | Custom roles are definable per workspace, down to individual fields. |
| Least-privilege integrations | In progress — not yet verified | Read-only OAuth scopes by default; write scopes are opted into per action class. |
| IP allowlisting, session timeout and MFA | In progress — not yet verified | Enforceable per workspace rather than per user. |
| Immutable audit log | In progress — not yet verified | Every mutation records actor, action, timestamp and result, with no PII payload. |
AI and data usage
| Item | Status | What that means |
|---|---|---|
| Customer data is never used to train foundation models | In progress — not yet verified | Contractual, and stated in the data processing addendum rather than only on this page. |
| Sub-processor list for model providers | In progress — not yet verified | Published on the sub-processor page with 30 days' notice before any change. Names: TODO-SUBSTANTIATE. |
| Agent actions logged with input, output and reasoning trace | In progress — not yet verified | Exportable, so an action can be reconstructed after the fact. |
| Human-in-the-loop approval gates per action class | In progress — not yet verified | You decide which actions reach a customer on their own and which wait for a person. |
| No customer data retained by model providers beyond the request | In progress — not yet verified | Depends on the provider contract; see the sub-processor page. |
Is my customer data used to train AI models?
Customer data is not training data. The agents read your stack to decide when to act; they do not learn from your accounts.
No. Maximus customer data is never used to train foundation models, and the commitment is contractual and recorded in the data processing addendum. Model providers are listed as sub-processors with their purpose, the data they process and their region, and the sub-processor page carries the notice period Maximus gives before that list changes.
Agent actions are visible rather than opaque. Every run records its trigger, the signals it read, the actions it took and whether a person approved it, and the trace is exportable. Approval gates are configurable per action class, so an action that reaches a customer can be made to require a human first.
The sub-processor names, regions and data categories are marked TODO-SUBSTANTIATE until the executed agreements are confirmed. See the sub-processor list.
Operational security
| Item | Status | What that means |
|---|---|---|
| Uptime SLA with a public status page | In progress — not yet verified | SLA percentage: TODO-SUBSTANTIATE. |
| Audit logs exportable to Splunk or Datadog | In progress — not yet verified | Immutable once written. |
| Critical patch SLA | In progress — not yet verified | Patch target: TODO-SUBSTANTIATE. |
| Incident response with root-cause analysis | In progress — not yet verified | Notification commitments are contractual and are being confirmed. |
| Vulnerability disclosure programme | In progress — not yet verified | Reports are triaged and acknowledged; coordinated disclosure is preferred. |
Request the SOC 2 report
The SOC 2 report and the penetration-test summary letter are sent under NDA. Tell us where to send it and who it is for.
Security overview
One page covering the same controls as this page, written to be forwarded to a CISO or a procurement reviewer.
The security overview is a one-page summary of the controls on this page: encryption, residency, access control, AI data usage and operational security. Enter a work email to download it.
The overview is sent to the address you give above.
Questions a security reviewer asks Maximus
Request it through the form on this page. Maximus sends the report under NDA, and the request is recorded as a security lead so it reaches the team directly rather than entering a general sales queue.
No. Maximus never uses customer data to train foundation models, and the commitment is written into the data processing addendum rather than resting on this page alone.
Maximus provisions workspaces in the United States, the European Union or India, and the region is chosen at provisioning time rather than after the fact.
Maximus publishes its sub-processors with their purpose, the data they process and their region, and gives 30 days' notice before a change to that list.
Yes. Agent runs and audit logs are exportable, retention is configurable per workspace, and a documented erasure process removes a record and its derived records within 30 days.
More answers in the FAQ hub and in the sub-processor list.
Send this page to your reviewer.
If the review needs a document, a control description or a call with the team, the request form above reaches them directly. Pricing and the full feature list are public, so nothing here waits on a sales conversation.
Figures marked TODO-SUBSTANTIATE are pending confirmation and are not published commitments.