Skip to content
Security & Governance

Security built into every layer of Maxley.

Maxley is designed around isolated infrastructure, gateway-mediated access, Maximo-native permissions, data privacy, auditability, and customer-controlled AI usage.

Maxley Security Model Gateway Enforced
User Session
Signed Token + Gateway
Maximo Permissions
Approved Data Access
Single-Tenant by DefaultEach Maxley deployment runs on dedicated infrastructure for that customer.
Gateway-Mediated AccessThe AI agent does not hold direct Maximo credentials or bypass user permissions.
Maximo-Native SecurityAccess is enforced using the same Maximo user, site, table, and application rules.
Security Philosophy

Maxley is designed so AI can assist without becoming a shortcut around security.

Maxley’s architecture is built to preserve Maximo permissions, minimize data retention, isolate customer environments, and keep access decisions in controlled gateway services instead of relying only on prompt instructions.

The same security-first thinking also supports the broader MaxStack ecosystem, including hosting, integrations, MaxProcure workflows, and customer-specific deployment models.

Core principles:

  • Dedicated infrastructure per customer
  • No shared customer compute paths for Maxley deployments
  • No direct Maximo API key access by the AI agent
  • Gateway-enforced permission checks
  • Optional read-only operation
  • Auditable access, query, and security events
Security Layers

Controls across infrastructure, access, data, updates, and auditability.

Architecture Flow

Maxley routes AI actions through controlled security checkpoints.

The AI agent does not receive unchecked access to Maximo. Requests flow through signed sessions, gateway validation, Maximo security enforcement, optional PII controls, and audit logging.

1

User Opens Maxley

Maxley inherits the customer’s existing Maximo authentication context.

2

Signed Session Token

Session tokens are HMAC-SHA256 signed and contain user, host, and expiration context.

3

Gateway Proxy

The gateway validates identity, permissions, query type, and allowed access before reaching Maximo.

4

Maximo Data Access

Approved calls follow Maximo’s user, table, site, application, and security profile rules.

Security controls are enforced in code, not just in model instructions.

Maxley is designed so critical restrictions are handled by infrastructure, gateway services, query parsers, proxy rules, token validation, and Maximo security checks.

Important enforcement points:

  • Maxley gateway holds the Maximo API key, not the AI agent
  • Every REST API call or query passes through a gateway proxy
  • SELECT-only query enforcement rejects non-read SQL
  • Read-only mode blocks write operations at the gateway level
  • Optional PII firewall blocks agent access to sensitive tables and fields
  • Security event logging records blocked access and proxy rejections
Detailed Controls

Security controls by category.

Common Security Questions

Security FAQ

Want to review the security model for your environment?

Talk through Maxley’s deployment model, gateway enforcement, Maximo permissions, data privacy, audit logging, read-only controls, and how security fits your organization.