Security

Compliance & privacy

AdminUpdated Sep 11, 2026

Our privacy posture, and an honest status on the certifications customers ask about.

GDPR

Atlas is built to support GDPR obligations for both the customers who run it and the end users whose data it holds:

  • Data subject requests. Atlas provides first-class APIs for data subject requests — access, export, and erasure — so a controller can fulfill an end user's rights programmatically rather than by hand.

  • Data portability. Import/export tooling lets you move tenant data in and out in a structured form.

  • Data minimization & residency. Atlas stores the identity data needed to authenticate and authorize, and nothing keeps state outside Postgres and Redis. Self-hosting keeps all personal data within your own infrastructure and region; see Data residency.

  • Right to erasure. Deletion propagates through the tenant-scoped data model, and encrypted secrets become unrecoverable once their keys are destroyed.

Data Processing Agreement

For the managed service, Atlas offers a Data Processing Agreement (DPA) covering our role as processor, the subprocessors we use, and the safeguards applied to international transfers. The current DPA is available at legal.atlasauth.net.

SOC 2 and ISO 27001 — status

We want to be precise here, because a Trust Center that implies certifications it does not hold is exactly the kind of overclaiming a security product should avoid.

  • SOC 2: Not yet certified. Establishing a SOC 2 program is on our roadmap. Many of the underlying controls a SOC 2 audit looks for — encryption at rest, access control, audit logging, change management, and secret handling — are already in place and described throughout this Trust Center, but no SOC 2 report exists yet, and we will not claim one until an auditor issues it.

  • ISO 27001: Not yet certified, and similarly on the roadmap.

  • Independent penetration test: an external penetration test is planned as a pre-launch gate and has not yet been completed. We will publish its status here rather than imply it retroactively.

If your procurement process needs a security questionnaire completed or a current controls summary in the meantime, contact security@atlasauth.net.

Subprocessors

For the managed service, the current list of subprocessors that may process personal data on our behalf is maintained at legal.atlasauth.net; a summary and how to receive change notifications are on the Subprocessors page. Self-hosted deployments introduce no Atlas-operated subprocessors — you choose your own infrastructure and vendors.

Was this page helpful?