Back
AxiPass
AxiPass

AxiPass Terms of Service

Effective date: July 13, 2026

AxiPass is a B2B Identity Provider built to securely provide enterprise SSO, app access management, audit logs, and automatic login features. These terms explain the rights and responsibilities that apply when using the AxiPass service and the AxiPass SWA Chrome extension.

Managed B2B service

AxiPass is a workplace service adopted and managed by customer organizations, not a public consumer service. User accounts, permissions, and app access policies are operated according to the user's organization administrator and AxiPass service settings.

Chapter 1. General provisions

Article 1(Purpose)

These terms set out the rights, obligations, and responsibilities and other necessary matters between 액시멈주식회사 (the "Company") and users (the customer organization that adopts the service and its members) in connection with the use of the AxiPass service (the "Service").

Article 2(Definitions)

The main terms used in these terms have the following meanings.

  • Service: all enterprise identity management features provided by AxiPass, including SSO, app access management, SCIM, MFA, audit logs, and SWA automatic login
  • Tenant: an isolated workspace for each customer organization that has adopted the service
  • Administrator: the person at the customer organization who configures and operates the tenant's members, permissions, and policies
  • Member (user): a user who belongs to a tenant and uses the service
  • SSO: unified authentication that logs in to multiple business apps with a single sign-in (OIDC/OAuth2, SAML)
  • SWA: Secure Web Authentication that securely auto-fills credentials into form-based business apps
  • Extension: the AxiPass Chrome extension that supports SWA automatic login

Article 3(Effect and amendment of the terms)

These terms take effect when a user uses the service. The Company may amend these terms within the bounds of applicable law and will give notice in-service or by email at least 7 days before the effective date (30 days for material or unfavorable changes). If a user continues to use the service after the effective date, they are deemed to have agreed to the amended terms.

Article 4(Protection of personal data)

The Company strives to protect users' personal data in accordance with applicable law. The collection, use, retention, and destruction of personal data are governed by a separate privacy policy, which can be found within the service.

Chapter 2. Use of the service

Article 5(Scope of service)

AxiPass provides features for managing enterprise accounts and business app access, including OIDC/OAuth2, SAML, SCIM, MFA, audit logs, app access policies, and SWA automatic login. Available features may vary by contract, tenant settings, and administrator configuration.

  • Single sign-on (SSO): authentication based on OIDC/OAuth2 and SAML 2.0
  • Directory integration: SCIM 2.0 provisioning (user and group sync)
  • Security: multi-factor authentication (MFA, TOTP), access rights and group policies
  • Automatic login: SWA (Secure Web Authentication) credential auto-fill
  • Audit and compliance: audit logs, CSV/PDF export, ISMS-P reports
  • Tenant management: member, group, and app registration, domain verification

Article 6(Accounts and permissions)

Users must use the service only within the account and permission scope assigned to them. Customer organization administrators are responsible for properly managing member invitations, roles, groups, app access policies, and account suspension or deletion.

  • Administrator responsibilities: properly managing member invitations, role and group assignment, app access policies, and account suspension or deletion
  • User responsibilities: using the service only within the account and permission scope assigned to them
  • Change and revocation: administrators may change or revoke permissions according to the organization's policy

Article 7(Management of authentication information and security)

Users must keep passwords, MFA methods, recovery codes, and SWA login permissions secure and must not share them with third parties. Suspected unauthorized access or account misuse should be reported promptly to the organization administrator or AxiPass.

  • Users must keep authentication information secure, including passwords, MFA methods, recovery codes, and SWA login permissions.
  • Authentication information must not be shared with or transferred to third parties.
  • Suspected account misuse or abnormal access must be reported promptly to the organization administrator or AxiPass.

Article 8(Use of the Chrome extension)

The AxiPass SWA Chrome extension is an auxiliary tool for approved business app logins. Users must not misuse the extension on unauthorized sites or use automatic login features to access another person's account or permissions.

Article 9(Service provision and interruption)

AxiPass strives to provide a stable service around the clock. However, it may temporarily suspend all or part of the service in the following cases.

  • Operational needs such as scheduled maintenance, server expansion or replacement, and security patches
  • Unavoidable cases such as power outages, network failures, or failures of external infrastructure (such as cloud providers)
  • The company gives advance notice of suspension and may give notice afterward in urgent or unavoidable cases.
  • The company is not liable for suspensions caused by events beyond its reasonable control, such as natural disasters.

Article 10(Changes to the service)

AxiPass may change the service or limit certain features for stability, security, legal compliance, or product improvement. Service scope, availability, and support conditions are governed by the customer contract and operating policies.

Article 11(Fees and refunds)

AxiPass paid plans are billed in advance at the start of each billing cycle based on the number of seats (users) and processed through the selected payment provider. Fees and billing cycles follow the customer agreement and pricing plan. Detailed rules for initial payments, renewals, plan changes, cancellations, and exceptional refunds are governed by the separate Refund Policy. If a payment fails, retries and payment-method update guidance are provided during a grace period, and some administrative features may be restricted if the issue remains unresolved for an extended time.

  • Paid plans are billed in advance at the start of each billing cycle based on the number of seats (users).
  • The first paid charge may be refunded in full once when requested within 7 days of the payment date.
  • Refunds involving renewals, plan changes, seat changes, and cancellations follow the separate Refund Policy.
  • If a payment fails, automatic retries occur during a grace period, and some administrative features may be restricted if it remains unresolved for an extended time.
  • To request a refund, contact your organization's administrator or [email protected].
View Refund Policy

Article 12(Retention and Deletion of Free Plan Accounts)

If a tenant on the Free plan does not access the service (including any authentication activity such as admin console sign-in or SSO authentication) for 7 consecutive days, the Company will notify the tenant administrator by email and grant a 7-day grace period from the date of notice (14 days in total from the first day of inactivity). If no access activity occurs within the grace period, the Company may permanently delete the tenant and all of its data, and deleted data cannot be recovered. This policy does not apply to paid plans.

  • If a Free plan tenant is inactive for 7 consecutive days, the administrator is notified by email.
  • If there is no access within the 7-day grace period after notice, the tenant and all its data are permanently deleted.
  • Deletion is cancelled if access such as admin console sign-in or SSO authentication is detected within the grace period.
  • Deleted data cannot be recovered. This policy does not apply to paid plans.

Chapter 3. Rights and obligations of the parties

Article 13(Company's obligations)

AxiPass complies with applicable law and these terms and strives to:

  • Provide the service continuously and stably
  • Operate a security framework to protect users' personal data and comply with the privacy policy
  • Promptly handle legitimate opinions or complaints raised by users

Article 14(User obligations and prohibited conduct)

In connection with use of the service, users must not do the following.

  • Unauthorized access to or bypass of another person's account or permissions
  • Disrupting normal operation of the service, causing abnormal traffic, or automated unauthorized collection (crawling, scraping)
  • Exploiting vulnerabilities, distributing malware, or attempting to compromise systems
  • Tampering with audit logs, or attempting to steal secrets or authentication information
  • Misusing the extension on unauthorized sites or bypassing the auto-fill feature
  • Infringing the rights of others, or acts contrary to law or public order and morals

Article 15(Content copyright and intellectual property)

Copyright and intellectual property in all content that makes up the service — software, design, trademarks, logos, and documents — belong to AxiPass (액시멈주식회사) or the rightful owner. Users may not reproduce, distribute, publish, or create derivatives of this content, or allow third parties to use it, without the company's prior written consent.

Article 16(Security incidents and audits)

AxiPass may retain and analyze logs as needed for security incident response, legal compliance, and customer audit support. Plaintext secrets are not written to audit logs as a default principle.

Chapter 4. Supplementary provisions

Article 17(Limitation of liability)

AxiPass is not liable for service disruptions caused by events beyond its reasonable control, such as natural disasters, war, power outages, failures of external infrastructure (such as cloud providers), or government orders. However, this limitation does not apply to damages caused by the company's intent or gross negligence.

Article 18(Governing law and dispute resolution)

These terms are governed by the laws of the Republic of Korea. Any dispute between the company and a user (or customer organization) arising from use of the service is resolved amicably through mutual consultation in principle; if not resolved, it is brought before the competent court under the Civil Procedure Act.

Article 19(Contact)

For service use, terms, or security reports, contact [email protected]. Users in managed tenants may first send account and permission requests to their organization's AxiPass administrator.

Business information

Company
액시멈주식회사
Representative
정은호
Business registration no.
445-87-02954
Mail-order business filing
No. 2026-Bucheon Wonmi-1246
Address
(14598) 경기도 부천시 원미구 송내대로73번길 46, 7층 D2호
Phone
010-3140-2180

This document applies to the AxiPass service and the AxiPass SWA Chrome extension. For inquiries, contact [email protected].