Skip to main content

Data flow of the axes4 desktop products

Data flow diagram. Inside the customer environment, the user works with the axes4 desktop product, which runs locally and calls the local License Manager. The product itself can also check for updates at axes4.com, outbound over HTTPS on TCP port 443; this check can be switched off. The License Manager uses exactly one licensing method: Active Directory in the customer LAN, an Entra ID tenant administered by the customer, or axes4 ID. Only axes4 ID crosses the trust boundary to the axes4 licensing servers.
Data flow of the axes4 desktop products. The table below states the same information in text form.
 
Document editing and checking in the axes4 desktop products run entirely on the client machine, and no document content is transmitted. Exactly two mechanisms can open an external connection: the update check, which can be switched off, and licensing. Licensing is configured in exactly one of three mutually exclusive methods, and only one of them leaves the customer network.

The three licensing methods

  Method 1 — Active Directory Method 2 — Entra ID Method 3 — axes4 ID
Peer Active Directory Domain Controller in the customer's own LAN Entra ID tenant under the customer's own control and administration axes4 licensing servers
Operated by Customer Customer axes4
Connection Customer LAN only, no internet contact Customer-controlled cloud tenant only Outbound only, HTTPS on TCP port 443. Inbound connections are not required and may be blocked completely.
Leaves the customer network No No Yes — this is the only method that does
Data transmitted None to axes4 None to axes4 Anonymized licensing data — see the field-level breakdown linked below
Retention Not applicable Not applicable The licensing data associated with the connection is retained by axes4 for 30 days
Purpose License validation License validation License assignment, feature enablement, targeted support, statistics

Update check

Independently of licensing, the products can check whether a newer version is available. This check is performed by the product itself, not through the License Manager.

  • Peer: https://axes4.com/<product>-latest-version
  • Direction: outbound only, HTTPS on TCP port 443
  • Purpose: determine whether a newer product version is available
  • Control: the check can be deactivated by an administrator or by the user. The product remains fully functional with the check switched off (axesWord, axesSlide, axesPDF).

Key statements

  • Document editing and checking run entirely on the client machine. No document content is transmitted anywhere.
  • The product communicates with a local License Manager component on the same machine.
  • The products can check whether a newer version is available. The product performs this check itself, not through the License Manager, by requesting https://axes4.com/<product>-latest-version over HTTPS. The check can be deactivated by an administrator or by the user.
  • Apart from the update check, licensing is the only possible external connection, configured in exactly one of three mutually exclusive methods.
  • With Active Directory or Entra ID licensing, no data leaves the customer's own network or the customer's own tenant, and there is no contact with axes4 servers.
  • With axes4 ID licensing, the License Manager opens an outbound-only HTTPS connection on TCP port 443 to the axes4 licensing servers. Inbound connections are never required and can be blocked entirely.
  • The data associated with that connection is retained by axes4 for 30 days and is used for license assignment, feature enablement, targeted support and statistics.

The complete field-level breakdown of the licensing data transmitted with axes4 ID licensing is documented here: Licensing data transmitted to axes4