Trust centre

What is in place, where your data lives, what is still open.

A security team prefers an accurate page to a reassuring one. Here is ours: the controls that exist in the product today, hosting as it is, and the work still open.

Security

The controls in place.

Only what exists in the code today. We walk your teams through the architecture on request.

  • Per-customer isolation

    Each organisation has its own data space; on the platform the database itself also enforces isolation.

  • Audit trail

    Creations, decisions, reviews, configuration and webhooks logged and timestamped, with their author; export from the console.

  • No personal data in logs

    Logs, audit, usage and webhooks carry only identifiers, statuses and reason codes.

  • Four-eyes approval

    A decision can require a second analyst, different from the first; handling time tracked.

  • Roles and sign-in

    Owner, administrator, developer, analyst, viewer; sign-in through OpenID Connect.

  • Versioned rules

    Each rule version is frozen: a verification keeps its rules, and its trace shows the path taken.

  • Keys and environments

    Keys shown only once and stored hashed; sandbox and production kept apart.

  • Encrypted traffic

    API, console and flow over HTTPS (TLS); signed webhooks so you can verify their origin.

  • Controlled callback addresses

    Webhook addresses must be public and HTTPS: never a call into an internal network.

Privacy

Personal data protection.

Atlas is designed around the principles shared by data protection laws: minimisation, consent, limited retention and individuals' rights. You remain responsible for your processing; Atlas carries it out for you.

Website privacy policy
  • Timestamped customer consent before any document is sent
  • You choose the accepted documents and the fields to extract
  • Biometrics deleted at closure by default
  • A customer and their data deleted through the API
  • PDF report per file for your own controls

Retention

Short retention, applied automatically.

An automatic pass applies your retention periods, and each deletion is logged, without personal data. Periods are set per customer.

  1. 01

    Biometrics

    Selfies and chip data deleted as soon as the verification ends, unless you choose to keep them.

  2. 02

    Documents and file data

    Captures, reports and extracted data deleted after a period you set (30 days by default).

  3. 03

    Decision record

    Status, decision, reasons and audit trail kept for your record-keeping obligations (5 years by default), then deleted.

  4. 04

    Abandoned verifications

    A verification never submitted is deleted 90 days after it was created.

Hosting

Where your data lives.

You choose hosting to fit your constraints. Before any pilot, we tell you where each component runs, AI models included.

  • Today

    Managed platform

    The Atlas platform (API, console, hosted flow) is hosted in the European Union. It is the fastest way to get started.

  • On request

    Regional hosting

    For organisations that must keep their data in a given region: a deployment in the cloud region of your choice, scoped to your requirements.

  • On request

    Dedicated deployment

    An instance reserved for your organisation, on a cloud of your choice or in your own infrastructure, to be scoped together.

Open work

What is still to do.

We would rather write it down. This work is open; ask us where it stands.

  • Certifications

    No security certification to date. We claim no standard until an audit has confirmed it.

  • Data protection filings

    Filings with the competent authorities are made country by country, before any real data is processed.

  • Per-customer encryption keys

    Encrypting stored data with a key specific to each customer is planned, together with the choice of hosting.

  • Security pack

    Detailed architecture, list of sub-processors and a data processing agreement template are coming; we will share them as soon as they are ready.

Security conversation

Does your security team have questions?

We present the architecture to your security, legal and compliance teams, and answer your questionnaires.