Trust, clearly stated.

Current information about Atlas security, privacy, AI services and the providers used to operate the platform.

Last updated 28 August 2026

Current assurance status.

Infrastructure assurance

Atlas relies on established infrastructure providers with their own assurance programmes. Current provider reports and contractual documentation can be reviewed during procurement where available.

Pimlico certification status

Pimlico Solutions is not represented on this site as currently holding SOC 2 or ISO 27001 certification. We provide the security evidence and programme status available at the time of customer review.

Privacy and contracting

Data-processing terms, transfer arrangements and the applicable service-provider schedule are available for customer review and are confirmed in the relevant agreement.

Core security controls.

Access control

Organisation membership and role-based permissions limit access to customer workspaces.

Authentication

Authentication controls include multi-factor options and supported enterprise sign-in configurations.

Data protection

Customer data is encrypted in transit and at rest within the services used to provide Atlas.

Operational evidence

Relevant administrative and product actions are recorded to support review and investigation.

Read the security overview

AI services in Atlas

Atlas uses source admission, bounded model tasks, human applicability review and controlled action rather than treating one model answer as a compliance decision. The provider, model and data arrangement depend on the feature and customer configuration.

Review the AI control model

Data, currentness and evidence

Regulatory coverage is maintained as a source perimeter with authority, version, capture time, refresh work and known boundaries. Citations, reviewer decisions and correction history make material outputs inspectable.

Custom LLM services

Custom LLM services are separately scoped. Model choice, approved data, hosting, access and retention are set out for the specific engagement rather than assumed from the standard Atlas service.

Service providers.

Services vary by customer configuration. The applicable provider list and transfer terms are confirmed in the relevant agreement and data-processing documentation.

Cloudflare

Website delivery, network security and edge services

Global network; contractual and transfer details are available during procurement.

Supabase

Application data, authentication and server-side functions

Hosting location and processing scope depend on the contracted service configuration.

Anthropic, OpenAI and Google

Approved AI model services

The provider and model depend on the Atlas feature and customer configuration.

Resend

Transactional email delivery

Used for service and account communications.

Stripe

Payment processing where card payment is used

Payment details are handled by Stripe under its own terms and privacy notice.

Atlassian Statuspage

Public service-status communications

Used to communicate service availability and incidents.

Need procurement or security documents?

Contact us for the current security questionnaire, DPA, provider documentation or service-specific review.