Skip to content

Your data stays where you put it.

The default deployment is your cloud, your keys, your model provider. We don’t train on your data, and every action a system takes is logged and reversible.

SOC 2 Type II · HIPAA · BYO VPC, keys and model

Audited, not self-certified.

Certifications tell you a process exists; they don’t tell you what happens to your data on a Tuesday. Each card carries the claim; open it for the scope, the auditor and the window.

In the normal engagement your data never leaves your cloud account. The system runs in your VPC, calls your model endpoints with your keys, and writes to your systems with credentials you issue and can revoke in one action.

We do not copy your data into our environment to build with, and we do not train models on it — that is a clause in the contract, not a setting in an admin panel.

Supporting documentation and scope are not published here. Request the current reports and applicable agreement before relying on a certification or compliance statement.

Scope
Not published
Auditor
Not published
Audit window
Not published
Scope
PHI stays in your perimeter; egress named in the blueprint
Auditor
Not published
Audit window
Per engagement, executed before the build starts
Scope
DPA with SCCs; EU-resident processing on the default deployment
Auditor
Not published
Audit window
Signed per engagement
Scope
Reference architecture and shared tooling
Auditor
Not published
Audit window
Not published

Not held today.

Listed here so nobody has to ask twice. We do not claim these.

  • ISO 27001 Not currently held.
  • Business continuity / DR targets Documented per engagement; no published group-level target yet.

Three deployment shapes. You pick one.

Pick a shape and the diagram moves. The first one is the default and the one we recommend; the third is the only one where anything at all sits with us.

Deployment shape

Everything runs inside your account. We hold nothing: no compute, no data, no keys, and credentials you can revoke in one action.

Your account Your cloud, your region

  • Compute Runs in your account
  • Data at rest Your storage, never copied out
  • Encryption keys Your KMS
  • Model provider Yours, including self-hosted open-weight
  • Network egress Controlled by you
  • Credentials Issued by you, revocable by you

AtomsAI Our account

Nothing sits here.

Typical use Regulated workloads, PHI and PII.

The same architecture in your account, operated by us. The only thing that changes is who holds the on-call pager and a scoped service account.

Your account Your cloud, your region

  • Compute Runs in your account
  • Data at rest Your storage
  • Encryption keys Your KMS
  • Model provider Yours
  • Network egress Controlled by you

AtomsAI Our account

  • Credentials Yours, scoped to our service account

Typical use You want the outcome, not the ops.

Ours end to end. It exists so a pilot can start on a Monday, and it is not where a regulated workload belongs.

Your account Your cloud, your region

Nothing sits here.

AtomsAI Our account

  • Compute Runs in our account
  • Data at rest Our storage
  • Encryption keys Managed KMS
  • Model provider Ours by default
  • Network egress Controlled by us
  • Credentials Held by us

Typical use Pilots and non-sensitive workloads. On request only.

Clouds
AWS · Google Cloud · Azure
Model providers
OpenAI · Anthropic · Amazon Bedrock · Google Vertex · self-hosted open-weight
Data residency
US · EU · India · Australia

Four commitments, in plain language.

  1. We don’t train on your data. Not for our models, not for a shared model, not anonymised, not aggregated. Contractual across every engagement.
  2. Your data doesn’t leave your perimeter by default. If a workflow genuinely requires egress, it’s named in the blueprint, approved by you before the build, and logged.
  3. Retention is your policy, not ours. We hold what your policy allows for as long as it allows, and we can show you where it sits.
  4. Deletion is a request, not a negotiation. On request or at contract end we delete and confirm in writing.

Sub-processors. The full sub-processor list — purpose, location and data category for each — is published separately. We give notice of any addition, and you can object.

Least privilege, and a log you can query.

Every system component and every AtomsAI engineer gets the narrowest credential that lets them do the job. Access is role-based per action rather than per system: an agent that reads invoices and writes to one ERP endpoint cannot read anything else, and that scope is reviewed with you at handover. Credentials are issued by you, and revoking them is one action on your side that stops everything.

Every run is logged with inputs, sources, decisions, the reasoning, the identity that authorised it and the outcome — and the log is in your environment, queryable by your own team. That’s what turns an audit request into a query and an incident review into an afternoon.

  • Role-based access per action Scopes documented and reviewed with you at handover.
  • Queryable audit trail In your environment, replayable per run.
  • Human approval gates Thresholds you set per workflow.
  • Reversible actions Idempotent writes, replay from any state, documented rollback.
  • Engineer access Background-checked, MFA-enforced, time-boxed and logged.
  • Incident response Named escalation path with a notification commitment in the contract.

Governance is set on the engine page, not promised on this one.

What a system may not do without a human is written down before it is built, and it drives the credentials, the staged writes, the holds and the rollback. Because it is configuration rather than architecture, you can start conservative and loosen it as the measured pass rate earns it. The control, the eval thresholds and the worst-case documentation all live with the build process.

How autonomy is set

Where to look, and who to tell.

Report a vulnerability
security@atomsai.com
Security questionnaires
security@atomsai.com
Privacy requests
privacy@atomsai.com

Bring your security team to the demo.

Bring the questionnaire too. Thirty minutes on deployment, keys, access and audit.

Book a call
Book a call

Request a thirty-minute session.

Tell us about your workflow. We’ll reply to arrange a time; submitting this form does not book a calendar slot.

We'll only use this to schedule your session. See our privacy policy.