Axenic
Axenic is a Wellington-based independent information security and privacy consultancy delivering governance, risk, assurance, architecture, and PCI DSS advisory services to NZ government agencies, private sector organisations, and NGOs, supported by a proprietary SaaS risk and assurance portal and GRC technology partnerships.
- Company typePrivate
- Founded2009
- HeadquartersWellington, New Zealand
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Axenic does
Axenic Limited is an independent information security and privacy consultancy headquartered in Wellington, New Zealand, founded in 2009 by Terry Chapman. The firm employs approximately 15 people and delivers advisory and assurance services to NZ government agencies (Ministry of Justice, Tertiary Education Commission, NZ Transport Agency), private sector organisations (iPayroll, Marketing Impact, WhosOnLocation), and not-for-profits (Human Rights Measurement Initiative, English Language Partners NZ). Its core proposition is vendor-independent advice — it does not sell products, partner with vendors (beyond complementary GRC technology), or perform technical implementation — and uses internationally recognised frameworks (ISO 27001/27002/27005/27031/27035/22301/31000, SABSA, COBIT, OCTAVE, PSR, NZISM, HISO 10029, GDPR) to deliver governance, risk, assurance, architecture, and PCI DSS consulting.
Axenic's technology backbone is the proprietary Axenic C&A (Certification and Accreditation) Portal, a SaaS platform developed since 2009 that standardises and automates risk and assurance activities, provides dashboards for risk owners, and measures organisational cybersecurity maturity. The portal is delivered in three packages — a C&A-as-a-Service Portal for government agencies, a Risk and Assurance Portal for commercial organisations, and a PCI Continuous Assurance Module — and is supplemented through two technology partner sub-brands: Axenic Powered by Archer (built on RSA Archer Integrated Risk Management) and Axenic Powered by 6Clicks (an AI-powered GRC platform partnership announced in April 2026). A third partnership with CyberHeed (June 2026) layers AI compliance automation on top of service delivery.
The business operates on a dual revenue model. The primary stream is professional services — project-based consulting and ongoing advisory engagements sold on a quote basis, acquired through direct enterprise outreach led by Terry Chapman, partner referrals, and content marketing (blog, newsletter, case studies, conference presence). The secondary stream is SaaS recurring revenue from C&A Portal subscriptions with tiered user roles, monthly billing in advance, and bundled 20-license increments. The firm holds ISO/IEC 27001:2013 certification and is a PCI Qualified Security Assessor (QSA) registered company, supporting premium pricing and regulatory positioning in a domestically focused market.
Axenic firmographics
Firmographics- Name
- Axenic
- Legal name
- Axenic Limited
- Website
- https://axenic.co.nz
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Axenic is a Wellington-based independent information security and privacy consultancy delivering governance, risk, assurance, architecture, and PCI DSS advisory services to NZ government agencies, private sector organisations, and NGOs, supported by a proprietary SaaS risk and assurance portal and GRC technology partnerships.
- Ownership category
- akta.pro rank
Axenic industry classification
Industry- Product category
- Information Security & Privacy Consulting
- NAICS
- Other Scientific and Technical Consulting Services (54169), Other Computer Related Services (541519)
- SIC
- Services-Business Services, Nec (7389), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Cybersecurity & Identity Consulting (BPAHAEAG)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Governance, Risk & Compliance (GRC) Managed Services (BPAEADAJ)
Keywords
Where Axenic is headquartered
LocationHeadquarters
- HQ city
- Wellington
- HQ country
- New Zealand
- HQ region
- Oceania
Offices1 record
Markets served
Axenic business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Professional Services / Consulting: Information security and privacy consulting services delivered by expert consultants including governance, risk assessment, assurance, architecture, and PCI DSS services. Revenue generated through project-based engagements and ongoing advisory relationships with clients.
- C&A Portal Subscription: SaaS subscription service for the Axenic C&A Portal with tiered access levels. Invoiced monthly in advance with pro-rata billing for part months. Additional user licenses charged in bundles of 20. 12-month initial term with automatic renewal.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | C&A Portal subscription with tiered user roles |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
Axenic product offering
Product offeringCore offering
Axenic provides independent information security and privacy consulting services across five practice areas — Governance, Risk, Assurance, Architecture, and PCI DSS — to government agencies, commercial organisations, and not-for-profits in New Zealand. The firm augments its advisory work with a proprietary SaaS platform (the Axenic C&A Portal for certification, accreditation, and continuous assurance) and partner-branded GRC platforms (Axenic Powered by Archer and Axenic Powered by 6Clicks). Service delivery spans ISO 27001 implementation and auditing, PSR/NZISM compliance, GDPR readiness, risk assessments, Privacy Impact Assessments, enterprise security architecture, and PCI DSS Qualified Security Assessor (QSA) engagements.
Product overview
Axenic is an independent information security and privacy consultancy offering a combination of professional consulting services and a proprietary SaaS platform. The core software product is the Axenic C&A (Certification and Accreditation) Portal, which standardises and automates risk and assurance activities and embeds Axenic's proprietary intellectual property developed since 2009. The company also delivers services through two partner technology platforms — Axenic Powered by Archer (built on RSA Archer's Integrated Risk Management platform) for PCI compliance, risk management, and audit management; and Axenic Powered by 6Clicks for AI-driven GRC and security compliance. The service portfolio spans five core practice areas: Governance (ISMS/ISO 27001, PSR, GDPR, vCISO), Risk (risk assessments, PIA, cloud assurance, business continuity), Assurance (certification audits, controls audits, internal audits), Architecture (enterprise security architecture, design reviews), and PCI DSS (QSA consulting and auditing).
Differentiator
Problem solved
Functional benefit
Brands
- Axenic Powered by Archer: SaaS portal for risk assessment, risk management and audit, combining Axenic professional services with Archer integrated risk management solutions
- Axenic Powered by 6Clicks
Products and services
- Axenic C&A Portal Proprietary SaaS platform that standardises and automates risk and assurance activities, provides dashboards for risk owners to manage cybersecurity risks, and measures organisational cybersecurity maturity through risk management and continuous assurance. Includes C&A as a Service for government agencies and a PCI Continuous Assurance Module. Invoiced monthly in advance with tiered user roles and additional user licenses sold in bundles of 20.
- Axenic Powered by Archer
Companies that use Axenic
Customer profileNamed customers8 records
Segments3 records
Ideal customer profiles3 records
Axenic technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Axenic partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- CyberHeedcorePartnership with CyberHeed enables Axenic to deliver smarter risk and compliance solutions using AI tools. CyberHeed builds AI tools for governance, risk and compliance, and their platform modernises the GRC lifecycle by unifying risk, compliance, and audit programmes into a single, automated system of record. For clients, this means accelerated compliance readiness and a clearer view of their risk landscape.
- 6clickscoreAxenic's partnership with 6clicks enables delivery of next-generation solutions that simplify risk and compliance for clients. The collaboration allows for centralised management of programmes, AI-driven automation of GRC processes, and simplified handling of multiple frameworks. Combined with Axenic's professional services, 6clicks supports modern cyber GRC, security compliance, vendor risk, ISMS and more through an AI-powered platform.
- Archer (RSM Holdings)coreAxenic Powered by Archer portal supports risk assessment, risk management, audit management, and PCI compliance. The partnership combines Axenic's professional services with Archer's integrated risk management solutions. Archer is the market leader in Integrated Risk Management solutions.
Scale indicators2 records
Recent moves7 records
Expansion highlights5 records
Axenic competitors and assessment
Company assessmentDirect peers
- Security-Assessment.com: NZ-headquartered independent cybersecurity assessment and consulting firm offering QSA, ISO 27001, and assurance services to enterprise and government across ANZ - directly comparable in service mix, QSA credentials, and NZ focus.
- Aura Information Security: New Zealand-based information security consultancy providing governance, risk, compliance and testing services to enterprise and government; similar client base and advisory-only positioning.
- Insomnia Security: NZ cybersecurity consultancy focused on offensive security testing and advisory for enterprise and public sector, overlapping with Axenic's risk assurance and governance services in the same geographic market.
- InPhySec: Wellington-based independent security consultancy delivering governance, risk, advisory and assurance services - a near-clone of Axenic's profile with overlapping customer segments in NZ government.
- Optic Security Group: ANZ physical and cyber security services provider combining consulting and managed security; broader in scale but overlaps with Axenic on advisory and risk services across Australasia.
Broad incumbents
- NCC Group: Global cybersecurity and assurance consultancy offering GRC, testing, and QSA-equivalent services; comparable at the service-category level but operates at much greater scale and geographic breadth than Axenic.
- Optiv: Large US-based cybersecurity solutions and services provider covering advisory, GRC, and managed security - relevant incumbent competing for enterprise GRC consulting budgets that Axenic also targets.
- A-LIGN: Global cybersecurity and compliance advisory firm with strong QSA and ISO 27001 assessment practice plus technology-enabled GRC delivery - comparable service stack and PCI/ISO focus but much larger and US-centric.
Emerging players
- Vanta: Automated compliance/GRC SaaS platform for ISO 27001, SOC 2, PCI and more - competes with Axenic's consulting-heavy model by enabling self-service, and complements it via the 6clicks/Archer channel.
Others
- 6clicks: AI-powered GRC technology platform that Axenic resells / co-delivers via "Axenic Powered by 6Clicks" - a strategic technology partner rather than competitor, but indicative of the platform category Axenic is building around.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks6 records
Key highlights7 records
Customer concentration
Axenic social profiles
Digital presenceAxenic compliance and trust
Trust signalCompliance2 records
Axenic financial estimates
Financial estimateRevenue estimate
Valuation estimate
Axenic leadership team
Management profileNumber of profiles
Profiles15 records
Axenic funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Axenic M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Axenic
What does Axenic do?
Axenic provides independent information security and privacy consulting services across five practice areas — Governance, Risk, Assurance, Architecture, and PCI DSS — to government agencies, commercial organisations, and not-for-profits in New Zealand. The firm augments its advisory work with a proprietary SaaS platform (the Axenic C&A Portal for certification, accreditation, and continuous assurance) and partner-branded GRC platforms (Axenic Powered by Archer and Axenic Powered by 6Clicks). Service delivery spans ISO 27001 implementation and auditing, PSR/NZISM compliance, GDPR readiness, risk assessments, Privacy Impact Assessments, enterprise security architecture, and PCI DSS Qualified Security Assessor (QSA) engagements.
Is Axenic a public or private company?
Axenic is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Axenic founded?
Axenic was founded in 2009. It employs 11 to 50 people.
Where is Axenic based?
Axenic is headquartered in Wellington, New Zealand, in the Oceania region.
How does Axenic make money?
Two revenue lines are on record. Professional Services / Consulting is the primary driver. The others are C&A Portal Subscription.
Who are Axenic's main competitors?
Direct peers on record are Security-Assessment.com, Aura Information Security, Insomnia Security, InPhySec and Optic Security Group. Broad incumbents are NCC Group, Optiv and A-LIGN. Vanta is listed as an emerging player. 6clicks is listed as an others.
Does Axenic have an API?
No public API is recorded for Axenic.
What industry is Axenic in?
Axenic's product category is Information Security & Privacy Consulting. Its primary akta.pro industry code is BPAHAEAG, Cybersecurity & Identity Consulting, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 54169 and its SIC code is 7389.