Security
AtlasAI doesn’t ask you to trust our security. It runs inside yours. Every deployment inherits the policies, controls, and compliance posture your firm has already built.
Visit Live Trust Center →How We Protect Your Firm
AtlasAI runs entirely within your firm’s Azure tenant. There is no external hosting, no shared compute, and no data leaving the environment your IT team already controls. The attack surface is yours to define.
Because AtlasAI operates inside your infrastructure, it inherits every policy you’ve already implemented—retention rules, DLP policies, conditional access, network segmentation. We don’t replace your controls. We operate within them.
Client data, work product, prompts, and AI outputs never leave your firm’s environment. No third-party vendor ever sees your data. No model provider receives your inputs. Privilege is maintained at every layer.
Every firm gets dedicated model instances running inside their own subscription. There is no shared inference, no multi-tenant processing, and no possibility of data leaking between organizations. Your AI is yours alone.
Our deployment agreement includes enforceable terms on data isolation, access restrictions, incident notification timelines, and ongoing compliance obligations. These aren’t marketing claims—they’re auditable contractual commitments.
We engage independent security firms to perform regular penetration testing and architecture reviews against our platform. Results are shared directly with deploying firms. We don’t ask you to take our word for it.
Two Ways to Deploy
AtlasAI is offered both as a managed cloud service and as a self-hosted deployment inside your firm’s own Microsoft Azure tenant. The control surface, encryption profile, audit logging, and compliance roadmap are identical across both models. The difference is who operates the infrastructure.
| Capability | Managed (Atlas-operated) | Self-Hosted (Your Azure tenant) |
|---|---|---|
| Hosting environment | Atlas-operated cloud environment; dedicated region available on enterprise plans | Your firm’s Microsoft Azure subscription, deployed via the templates we provide |
| Data residency | United States by default; EU, UK, and Canada available on enterprise plans | Wherever your firm places the resource group — any region you operate in |
| Encryption at rest | AES-256, service-managed keys; customer-managed keys on enterprise plans | AES-256 with your firm’s customer-managed keys by default |
| Encryption in transit | TLS 1.2+ end-to-end | TLS 1.2+ end-to-end |
| Identity & SSO | SAML / OIDC single sign-on; MFA enforced for workforce | Native integration with your enterprise identity provider; your existing conditional-access and MFA policies apply unchanged |
| Audit logging | Application + infrastructure logs centralized with 365-day retention; customer-accessible export | All logs land inside your environment and stream directly into your SIEM |
| AI model inference | In-region enterprise LLM endpoints with contractual zero data retention; no customer data used for training | Enterprise LLM endpoints in your tenant, or a fully private model endpoint you operate |
| Sub-processors | Full list disclosed in the Trust Center; 30-day change notice | None — everything runs inside your tenant under your existing DPAs |
| Backups & recovery | 30-day point-in-time database restore; soft-delete and versioning on object storage; quarterly restore drills (last validated 2026-05-28) | Same baseline templates; your firm tunes retention to its own standards |
| Incident response | Atlas IR team; 72-hour customer notification SLA | Your IR team owns the response; Atlas provides forensic support under contract |
| Compliance attestation | SOC 2 Type 1 audit in flight (Q3 2026); HITRUST CSF e1 aligned; BAA available | Inherits your firm’s existing SOC 2 / HITRUST / HIPAA attestations |
| Best fit | Faster onboarding; in-house teams, mid-market firms, and groups standardizing on a managed service | AmLaw 200, regulated industries (healthcare, banking, government), and firms with mature in-house security programs |
AtlasAI is architected to operate within the compliance frameworks your firm has already established. Because we deploy inside your environment, certification alignment is inherited by design—not bolted on after the fact.
Visit Live Trust Center →Most legal AI vendors ask firms to send their most sensitive data to external servers and trust that someone else will protect it. AtlasAI inverts that model entirely. By deploying inside your existing infrastructure, every security investment your firm has already made—firewalls, SIEM, identity governance, network policies—applies to AtlasAI automatically. There is no new perimeter to defend. There is no vendor to audit. The platform operates under the same security controls as the rest of your firm’s systems.
Visit Live Trust Center →Answers covering both AtlasAI managed-SaaS deployments and self-hosted deployments inside your firm’s own Azure tenant. For anything not covered here, request access to our Trust Center or email security@atlas-ai.io.
Walk through AtlasAI’s architecture with your security team. We’ll show you exactly where your data lives, who can access it, and why the answer to both is “only you.”
Start Free Trial