
A comprehensive overview of leadership hierarchy and reporting relationships supporting SOC 2 compliance requirements
Erika Bahr serves as CEO and holds ultimate accountability for Daxe Inc.'s strategic direction, investor relations, and organizational compliance. Her responsibilities encompass overall company governance, ensuring alignment between business objectives and regulatory requirements, and maintaining oversight of all compliance frameworks including SOC 2.
The CEO role is critical to establishing the tone at the top for security and compliance culture. Erika directly oversees the Technical Leadership function and maintains visibility across all business units to ensure consistent application of security controls and organizational policies.
Before founding Daxe, Erika led Data Strategy and Analytics at Merkle, where she managed analytics operations for nine Fortune 500 clients, optimizing over $45 million in annual media spend and developing machine learning models that predicted marketing ROI within 10% accuracy. Earlier, she worked on large-scale data engineering and analytics initiatives for global companies across technology, insurance, and financial services.
Erika holds advanced education from Harvard University’s Business Analytics Program, the University of Virginia Darden School of Business, and Brigham Young University, where she was a multiple-time academic scholarship recipient. She’s also a member of Beta Gamma Sigma and Omicron Delta Kappa honor societies, and a UVA Batten Institute i.Lab entrepreneurship grant recipient.
Under her leadership, Daxe has been selected for programs including NVIDIA Inception, BMO WMNFintech (1871), Google for Startups Innovate, and the U.S. Department of Defense NSIN FedTech Accelerator. Erika is a frequent speaker on the future of AI, compliance, and data ethics—recently addressing audiences at Harvard, the U.S. Patent & Trademark Office, and the Department of Energy.

Nathan Standiford - CTO
Oversees product architecture, technical roadmap, and all data security controls. Responsible for GraphRAG infrastructure implementation and SOC 2 compliance frameworks across technical operations.
The CTO position reports directly to the CEO and serves as the primary technical authority for all security and compliance matters. This role bridges executive leadership with engineering operations, ensuring technical implementations align with compliance requirements and business objectives.

Luis Cuadros is a Senior AI Architect | Generative AI Strategist, Remote/Global. He has 7+ years of experience designing and deploying enterprise-grade AI ecosystems for Government, Fintech, and Logistics sectors. Expert in Generative AI (RAG, Agents), MLOps governance, and high-performance inference architectures.
Luis reports directly to the CTO and leads AI architecture and engineering initiatives.
Jananadi Wedagedara directs all user interface and user experience design efforts, managing the implementation of customer-facing features and workflows.
Jananadi oversees the integration of Daxe's secure data room interface and AI-powered workflows, ensuring that security controls are properly implemented in all user-facing components. This includes managing front-end authentication, authorization flows, and secure data handling in the browser.
The front-end development function reports to the CTO and works in close coordination with backend engineering to ensure seamless and secure integration of all system components.
Benjamin Wang serves as AI Engineering Intern, supporting critical research and development initiatives in artificial intelligence.

Benjamin contributes to the development and evaluation of agentic AI systems, search algorithm optimization, and performance benchmarking initiatives. This work is essential to Daxe's competitive advantage and requires careful attention to data security and model governance.
The AI engineering function operates under the supervision of the CTO, with work products subject to security review and compliance validation before deployment to production environments.

Erika Bahr maintains overall organizational oversight and sets strategic direction for all business and technical operations.
Nathan Standiford reports directly to the CEO and manages all technical functions including engineering, front-end development, and AI research.
Senior AI Architect (Luis Cuadros), Head of Front-End (Jananadi Wedagedara), and AI Engineering Intern (Benjamin Wang) all report to the CTO.
This structure ensures clear accountability for security controls, compliance requirements, and technical decision-making across the organization.
The Daxe organizational chart is maintained as a living document within the company's shared Google Drive infrastructure, specifically within the Company Wiki folder under the path /Company/HR/Org Chart/.
This centralized approach ensures that all employees and contractors have access to current organizational information, supporting transparency and compliance requirements. The chart serves as official evidence for SOC 2 audits and internal control testing.
The organizational chart undergoes formal review and updates on a quarterly basis at minimum, or more frequently when organizational changes occur. Updates are communicated through two primary channels:
Organizations must maintain formal job descriptions for all existing positions, upcoming roles, and C-Suite positions. Each description should clearly define basic role requirements, expected responsibilities, and reporting relationships.
When multiple individuals occupy the same role (e.g., multiple senior software engineers), a single comprehensive job description is adequate. The description should outline the core requirements and responsibilities applicable to all individuals in that position.
Job descriptions must be freely available to everyone within the organization. If not facilitated through an HR platform, organizations should create a shared document repository (e.g., Google Docs) that is regularly updated as new roles are added or existing roles evolve.
Organizations must maintain awareness of and document all relevant statutory, regulatory, and contractual obligations that apply to their operations. This documentation serves as critical evidence during SOC 2 audits and demonstrates management's commitment to legal and regulatory compliance.
Requirements related to statutes and laws, including obligations to perform or refrain from specific actions as set out by state or federal law. Examples include compliance with the Sarbanes-Oxley Act, trademark protections, and labor laws.
Requirements stemming from government agency rules and regulations. Examples include standards set by OSHA, EPA, SEC, FDIC, or GDPR for organizations operating in applicable jurisdictions and industries.
Commitments made by the company through contractual agreements with customers, partners, or vendors. This includes contractual requirements to provide SOC 2 reports, maintain specific security controls, or adhere to service level agreements.
Organizations should maintain a centralized tracking document (spreadsheet or database) that identifies each applicable obligation, the source of the requirement, responsible parties, and verification procedures. This tracking mechanism should be reviewed and updated regularly to reflect changes in the regulatory landscape or business operations.
Our RBAC matrix clearly defines access permissions across critical systems for each role, enhancing security and streamlining compliance. This matrix ensures that personnel have appropriate access levels to perform their duties while minimizing risks.
Access Codes: F = Full Admin Access | L = Limited / Contributor Access | V = View-Only | N = No Access
Regular review of this RBAC matrix is crucial for maintaining a strong security posture and adhering to compliance standards, especially for sensitive data and systems.

Daxe Inc. Organizational Structure