Atlas handles your leads, customers, documents, and conversations. Here's exactly how we protect that data, who can see it, and what rights you have over it.
Ask a security question→Atlas plugs into your phone, inbox, calendar, spreadsheets, and CRM without ever asking for a password.
Only what's necessary to run the automations you bought. Nothing else.
Things we explicitly never touch, so you don't have to wonder.
Physical infrastructure, by tier. Your data & connected accounts stay isolated — never co-mingled. You can ask which region you're hosted in at any time.
Industry-standard everywhere, no exceptions.
| Layer | Standard | Notes |
|---|---|---|
| Data in transit | TLS 1.3 | All API traffic · web traffic · webhooks |
| Data at rest | AES-256 | Database · backups · object storage |
| Your connection credentials | Application-layer encryption (Fernet/AES) | Slack, Google & CRM tokens are encrypted inside the database — the decryption key lives only in the runtime environment, so a copy of the database alone can't read them |
| Application logs | PII-scrubbed | Customer message content is never written to logs · phone numbers & emails are masked · full detail lives only in your client-scoped, retention-swept audit log |
| Database backups | AES-256 + encrypted-at-rest snapshots | Stored in separate region from primary |
| API keys & secrets | Encrypted in secrets manager | Rotated quarterly · never in plain-text logs |
| Session tokens | HMAC-signed · short-lived | Slack/Twilio webhook signature verification on every request |
Every text Atlas sends is opt-out-safe. STOP is honored automatically, at the lowest level of every send path — so no skill can ever bypass it.
Atlas doesn't talk to your customers unsupervised on day one. It earns that.
Every marketing email Atlas sends on your behalf is built to the CAN-SPAM standard automatically — on every send path, with no exceptions.
Atlas never invents a price. Any number that goes out to a customer is checked against your real catalog before it leaves the building.
Every action Atlas takes is written to an append-only audit log. Nothing is silently edited or erased.
A short, accountable list.
Access controls in place:
Every third-party service we use, what data they touch, and their certifications. We notify you in writing before adding new ones.
| Service | Purpose | Data shared | Compliance |
|---|---|---|---|
| Anthropic claude.ai |
AI text generation (Atlas's brain) | Conversation contents at inference time only | SOC 2 Type II |
| Twilio twilio.com |
SMS & voice for Receptionist + Speed to Lead | Phone numbers · SMS bodies | SOC 2 + HIPAA |
| Groq groq.com |
Fast AI inference (router fast-path for simple text) | Conversation contents at inference time only · not used for training | SOC 2 Type II |
| Google Workspace google.com |
Sheets · Gmail · Calendar (under your OAuth) | Whatever you grant via OAuth scopes | SOC 2 + ISO 27001 |
| Railway railway.app |
Compute hosting (Core & Pro tiers) | App code + database | SOC 2 Type II |
| Hetzner Cloud hetzner.com |
Dedicated compute (Enterprise tier) | App code + database (isolated VPS) | ISO 27001 |
| Stripe stripe.com |
Billing & payments | Your billing details · we never see card numbers | PCI DSS Level 1 |
| Vercel vercel.com |
Demo hub + public marketing site only | No customer data · static files only | SOC 2 Type II |
| Slack slack.com |
Atlas's chat interface (your workspace) | Messages you send Atlas | SOC 2 + ISO 27001 + FedRAMP |
Where we stand today and what's coming.
| Standard | Status | Notes |
|---|---|---|
| SOC 2 Type II | On roadmap | Planned as we scale · every infrastructure sub-processor we run on (Railway, Anthropic, Twilio, Stripe, Slack) is independently SOC 2 audited today. |
| GDPR-ready | Yes | EU clients hosted in Hetzner (Germany) · DPA available on request |
| CCPA-compliant | Yes | California Consumer Privacy Act · right-to-delete honored within 30 days |
| TCPA · A2P 10DLC | Registered at onboarding | We file your carrier registration during setup (approval typically 1–2 weeks) · STOP auto-honored on every send path |
| HIPAA | Enterprise tier only | Custom BAA available · only when explicitly contracted |
| Annual penetration test | Planned 2027 | Will be commissioned once we reach 10+ Enterprise clients |
How long we keep your data, and what happens when you leave. Retention is configurable per client — tell us your policy and we'll set it.
The defaults below are exactly that — defaults. We can shorten or lengthen retention windows to match your internal policy or your insurer's requirements. Just say the word and we configure it for your account.
It's your business. It's your data. No locked-in clauses.
What we'll do — and how fast — if something goes wrong.
| Event type | Notification SLA | Report SLA |
|---|---|---|
| Data breach affecting your records | Within 24 hours of discovery | Detailed post-mortem within 7 days |
| Service outage > 30 minutes | Within 1 hour | Public status page update + email recap |
| Unauthorized access attempt (blocked) | Monthly summary | Included in standard audit log |
| Sub-processor incident (e.g. Anthropic outage) | Within 2 hours of confirmation | Status update as situation evolves |
Additional commitments included when you're on the Atlas Enterprise plan. The dedicated-infrastructure guarantees below apply to Enterprise only.
Comes with dedicated infrastructure and signed contractual guarantees beyond what's listed above. These dedicated-server / own-VPS / own-Postgres commitments are scoped to the Enterprise tier.
Real humans, real responses. Most queries answered within one business day.
Need an NDA, DPA, BAA, security questionnaire response, or SIG Lite filled out? Email security@lilesautomation.com and we'll turn it around within 3 business days.