Trust centre
What is in place, where your data lives, what is still open.
A security team prefers an accurate page to a reassuring one. Here is ours: the controls that exist in the product today, hosting as it is, and the work still open.
Security
The controls in place.
Only what exists in the code today. We walk your teams through the architecture on request.
-
Per-customer isolation
Each organisation has its own data space; on the platform the database itself also enforces isolation.
-
Audit trail
Creations, decisions, reviews, configuration and webhooks logged and timestamped, with their author; export from the console.
-
No personal data in logs
Logs, audit, usage and webhooks carry only identifiers, statuses and reason codes.
-
Four-eyes approval
A decision can require a second analyst, different from the first; handling time tracked.
-
Roles and sign-in
Owner, administrator, developer, analyst, viewer; sign-in through OpenID Connect.
-
Versioned rules
Each rule version is frozen: a verification keeps its rules, and its trace shows the path taken.
-
Keys and environments
Keys shown only once and stored hashed; sandbox and production kept apart.
-
Encrypted traffic
API, console and flow over HTTPS (TLS); signed webhooks so you can verify their origin.
-
Controlled callback addresses
Webhook addresses must be public and HTTPS: never a call into an internal network.
Privacy
Personal data protection.
Atlas is designed around the principles shared by data protection laws: minimisation, consent, limited retention and individuals' rights. You remain responsible for your processing; Atlas carries it out for you.
Website privacy policy- Timestamped customer consent before any document is sent
- You choose the accepted documents and the fields to extract
- Biometrics deleted at closure by default
- A customer and their data deleted through the API
- PDF report per file for your own controls
Retention
Short retention, applied automatically.
An automatic pass applies your retention periods, and each deletion is logged, without personal data. Periods are set per customer.
- 01
Biometrics
Selfies and chip data deleted as soon as the verification ends, unless you choose to keep them.
- 02
Documents and file data
Captures, reports and extracted data deleted after a period you set (30 days by default).
- 03
Decision record
Status, decision, reasons and audit trail kept for your record-keeping obligations (5 years by default), then deleted.
- 04
Abandoned verifications
A verification never submitted is deleted 90 days after it was created.
Hosting
Where your data lives.
You choose hosting to fit your constraints. Before any pilot, we tell you where each component runs, AI models included.
- Today
Managed platform
The Atlas platform (API, console, hosted flow) is hosted in the European Union. It is the fastest way to get started.
- On request
Regional hosting
For organisations that must keep their data in a given region: a deployment in the cloud region of your choice, scoped to your requirements.
- On request
Dedicated deployment
An instance reserved for your organisation, on a cloud of your choice or in your own infrastructure, to be scoped together.
Open work
What is still to do.
We would rather write it down. This work is open; ask us where it stands.
Security conversation
Does your security team have questions?
We present the architecture to your security, legal and compliance teams, and answer your questionnaires.