Security built into every layer of Maxley.
Maxley is designed around isolated infrastructure, gateway-mediated access, Maximo-native permissions, data privacy, auditability, and customer-controlled AI usage.
Maxley is designed so AI can assist without becoming a shortcut around security.
Maxley’s architecture is built to preserve Maximo permissions, minimize data retention, isolate customer environments, and keep access decisions in controlled gateway services instead of relying only on prompt instructions.
The same security-first thinking also supports the broader MaxStack ecosystem, including hosting, integrations, MaxProcure workflows, and customer-specific deployment models.
Core principles:
- Dedicated infrastructure per customer
- No shared customer compute paths for Maxley deployments
- No direct Maximo API key access by the AI agent
- Gateway-enforced permission checks
- Optional read-only operation
- Auditable access, query, and security events
Controls across infrastructure, access, data, updates, and auditability.
Maxley routes AI actions through controlled security checkpoints.
The AI agent does not receive unchecked access to Maximo. Requests flow through signed sessions, gateway validation, Maximo security enforcement, optional PII controls, and audit logging.
User Opens Maxley
Maxley inherits the customer’s existing Maximo authentication context.
Signed Session Token
Session tokens are HMAC-SHA256 signed and contain user, host, and expiration context.
Gateway Proxy
The gateway validates identity, permissions, query type, and allowed access before reaching Maximo.
Maximo Data Access
Approved calls follow Maximo’s user, table, site, application, and security profile rules.
Security controls are enforced in code, not just in model instructions.
Maxley is designed so critical restrictions are handled by infrastructure, gateway services, query parsers, proxy rules, token validation, and Maximo security checks.
Important enforcement points:
- Maxley gateway holds the Maximo API key, not the AI agent
- Every REST API call or query passes through a gateway proxy
- SELECT-only query enforcement rejects non-read SQL
- Read-only mode blocks write operations at the gateway level
- Optional PII firewall blocks agent access to sensitive tables and fields
- Security event logging records blocked access and proxy rejections
Security controls by category.
Security thinking across the MaxStack ecosystem.
Maxley has the most AI-specific security model, but the same principles apply across the broader platform: isolated infrastructure, controlled access, auditability, and customer-aware implementation.
AI for Maximo
Context-aware AI with gateway-enforced Maximo permissions, customer-controlled AI provider access, and audit trails.
MaxStack PlatformDedicated MAS Hosting
Dedicated environments and deployment patterns designed for control, performance, and customer-specific access needs.
MaxProcureProcurement Workflows
Vendor, purchasing, accounting, and procurement workflows can be implemented with controlled access and audit visibility.
Security FAQ
Want to review the security model for your environment?
Talk through Maxley’s deployment model, gateway enforcement, Maximo permissions, data privacy, audit logging, read-only controls, and how security fits your organization.
