Security & Trust
Atlas processes sensitive business documents. Here is exactly how we protect them - where data lives, who can access it, and how long we keep it.
At a glance
Policy documents
All policies are version-controlled and publicly auditable on GitHub.
How Atlas protects data at rest and in transit - KMS key inventory, rotation procedures, and SOC 2 controls CC6.1 and CC6.7.
Retention periods for source documents, workflow data, and audit logs - and how data is deleted on request. SOC 2 controls C1.2 and P4.2.
Every third party that handles customer data - AWS (S3, DynamoDB, Bedrock, Cognito, AppSync), and GitHub for CI/CD. Regions, contracts, and DPA status.
Questions
To report a vulnerability, request a data deletion, or ask about our compliance posture, email security@atlasweave.ai.