AtlasAI Trust Center is live — 66 of 68 SOC 2 + HITRUST e1 controls compliant
Open Trust Center →

Security

Your Infrastructure.
Your Rules.

AtlasAI doesn’t ask you to trust our security. It runs inside yours. Every deployment inherits the policies, controls, and compliance posture your firm has already built.

Visit Live Trust Center →

How We Protect Your Firm

Deployed Inside Your Perimeter

AtlasAI runs entirely within your firm’s Azure tenant. There is no external hosting, no shared compute, and no data leaving the environment your IT team already controls. The attack surface is yours to define.

Inherits Your Compliance Posture

Because AtlasAI operates inside your infrastructure, it inherits every policy you’ve already implemented—retention rules, DLP policies, conditional access, network segmentation. We don’t replace your controls. We operate within them.

Zero Data Exposure to Third Parties

Client data, work product, prompts, and AI outputs never leave your firm’s environment. No third-party vendor ever sees your data. No model provider receives your inputs. Privilege is maintained at every layer.

Your Models. Isolated.

Every firm gets dedicated model instances running inside their own subscription. There is no shared inference, no multi-tenant processing, and no possibility of data leaking between organizations. Your AI is yours alone.

Contractually Binding Protections

Our deployment agreement includes enforceable terms on data isolation, access restrictions, incident notification timelines, and ongoing compliance obligations. These aren’t marketing claims—they’re auditable contractual commitments.

Continuous Validation

We engage independent security firms to perform regular penetration testing and architecture reviews against our platform. Results are shared directly with deploying firms. We don’t ask you to take our word for it.

Two Ways to Deploy

Cloud-Hosted or Inside Your Tenant — Same Security Posture

AtlasAI is offered both as a managed cloud service and as a self-hosted deployment inside your firm’s own Microsoft Azure tenant. The control surface, encryption profile, audit logging, and compliance roadmap are identical across both models. The difference is who operates the infrastructure.

Capability Managed (Atlas-operated) Self-Hosted (Your Azure tenant)
Hosting environment Atlas-operated cloud environment; dedicated region available on enterprise plans Your firm’s Microsoft Azure subscription, deployed via the templates we provide
Data residency United States by default; EU, UK, and Canada available on enterprise plans Wherever your firm places the resource group — any region you operate in
Encryption at rest AES-256, service-managed keys; customer-managed keys on enterprise plans AES-256 with your firm’s customer-managed keys by default
Encryption in transit TLS 1.2+ end-to-end TLS 1.2+ end-to-end
Identity & SSO SAML / OIDC single sign-on; MFA enforced for workforce Native integration with your enterprise identity provider; your existing conditional-access and MFA policies apply unchanged
Audit logging Application + infrastructure logs centralized with 365-day retention; customer-accessible export All logs land inside your environment and stream directly into your SIEM
AI model inference In-region enterprise LLM endpoints with contractual zero data retention; no customer data used for training Enterprise LLM endpoints in your tenant, or a fully private model endpoint you operate
Sub-processors Full list disclosed in the Trust Center; 30-day change notice None — everything runs inside your tenant under your existing DPAs
Backups & recovery 30-day point-in-time database restore; soft-delete and versioning on object storage; quarterly restore drills (last validated 2026-05-28) Same baseline templates; your firm tunes retention to its own standards
Incident response Atlas IR team; 72-hour customer notification SLA Your IR team owns the response; Atlas provides forensic support under contract
Compliance attestation SOC 2 Type 1 audit in flight (Q3 2026); HITRUST CSF e1 aligned; BAA available Inherits your firm’s existing SOC 2 / HITRUST / HIPAA attestations
Best fit Faster onboarding; in-house teams, mid-market firms, and groups standardizing on a managed service AmLaw 200, regulated industries (healthcare, banking, government), and firms with mature in-house security programs

Compliance you don’t
have to build around

AtlasAI is architected to operate within the compliance frameworks your firm has already established. Because we deploy inside your environment, certification alignment is inherited by design—not bolted on after the fact.

Visit Live Trust Center →
SOC 2 Type 1

Readiness complete · CPA audit Q3 2026

Details
HITRUST CSF e1

Aligned across 31 controls

Details
HIPAA-Ready

BAA available on enterprise plans

Details
GDPR & CCPA

Standard DPA + sub-processor disclosure

Details

The Safest AI Is the AI You Already Control

Most legal AI vendors ask firms to send their most sensitive data to external servers and trust that someone else will protect it. AtlasAI inverts that model entirely. By deploying inside your existing infrastructure, every security investment your firm has already made—firewalls, SIEM, identity governance, network policies—applies to AtlasAI automatically. There is no new perimeter to defend. There is no vendor to audit. The platform operates under the same security controls as the rest of your firm’s systems.

Visit Live Trust Center →

Common Questions

Answers covering both AtlasAI managed-SaaS deployments and self-hosted deployments inside your firm’s own Azure tenant. For anything not covered here, request access to our Trust Center or email security@atlas-ai.io.

Where does AtlasAI run? Cloud or on-premises?
Both. AtlasAI is available as a managed cloud service (United States by default; EU, UK, and Canada available on enterprise plans) and as a self-hosted deployment inside your firm’s own Microsoft Azure tenant. The architecture, encryption profile, audit logging, and compliance roadmap are identical across both models — the difference is who operates the infrastructure. We do not offer multi-cloud or shared-compute deployments.
How is customer data defined?
Customer data means everything you upload (documents, contracts, deal rooms, knowledge-graph inputs) and everything you generate using the platform (prompts, AI responses, chat history, workspace artifacts). All of it is treated as Restricted under our Data Classification Policy: encrypted at rest with AES-256, encrypted in transit with TLS 1.2+, accessible only to the authorized users you designate, and logged on every access.
Is our data ever used to train or improve models?
No. Your inputs, outputs, uploaded documents, and interaction data are never used to train, fine-tune, or improve any model — AtlasAI’s, our LLM providers’, or any third party’s. This is contractual in our Master Subscription Agreement and enforced by Zero Data Retention terms in our agreements with every approved LLM provider. If your firm wants to fine-tune a private model on its own data for its own use, that capability exists in self-hosted deployments and the model + data stay entirely inside your tenant.
What encryption is used, and who holds the keys?
All data at rest is encrypted with AES-256 (service-managed by default on the managed cloud service; customer-managed keys on enterprise plans and on self-hosted deployments). All data in transit uses TLS 1.2 or higher. Application secrets are stored in a hardware-backed secrets vault with soft-delete and purge protection; the application accesses them via managed identity, never via embedded credentials. Customer-managed key support means you can hold and rotate the root encryption keys on your own HSM and revoke our access at any time.
Who are your sub-processors?
For the managed cloud service, the categories of sub-processors are: enterprise cloud infrastructure, in-region LLM inference, authentication, billing, and source-control / CI. Every sub-processor is bound by a Data Processing Agreement. The complete current list of named vendors is maintained in our Trust Center and available to customers and prospects under NDA; we provide at least 30 days’ notice before any material change. For self-hosted deployments there are no AtlasAI sub-processors — everything runs inside your own tenant under your existing DPAs.
Where is data hosted and processed?
Managed cloud service: the default region is the United States. Dedicated European Union, United Kingdom, and Canada regions are available on enterprise plans. LLM inference happens in the same region as the data — no cross-region traffic. Self-hosted: wherever your firm places the resource group. We support any Microsoft Azure region your subscription has access to.
How are access controls and SSO handled?
All access is authenticated and authorized server-side on every request. The managed cloud service supports SAML / OIDC single sign-on, password-complexity enforcement, and multi-factor authentication. Self-hosted integrates natively with your firm’s enterprise identity provider — your existing conditional-access policies, MFA, and identity governance apply unchanged. Inside the application, tenant-scoped roles (super-admin, admin, member, viewer) gate every action, and per-matter access is configurable down to the document level.
What audit logging do you provide?
Every security-relevant action is logged at two layers: an application audit log (sign-ins, document opens, chat queries, admin changes) and the underlying infrastructure logs (database access, object-store activity, secret-vault operations, request traffic). The managed cloud service retains both for 365 days in our centralized logging platform with customer-accessible export. Self-hosted: all logs land in your firm’s own logging platform and stream directly into your SIEM — we never need a copy.
How are AI models isolated between customers?
In the managed cloud service, inference goes through an enterprise LLM endpoint in the same region as your data under contractual Zero Data Retention — no model state persists between requests, and customer queries are not visible to other tenants. In self-hosted, you can use an enterprise LLM endpoint in your own tenant or a fully private model endpoint you operate. Knowledge-graph and vector embeddings are partitioned per-tenant in both modes; customers on enterprise plans may elect a fully dedicated logical database.
What about HIPAA, BAAs, and healthcare data?
AtlasAI operates on HIPAA-eligible infrastructure and offers a Business Associate Agreement (BAA) for enterprise plans. The platform’s control set is mapped to the HITRUST CSF entry tier (e1) and the relevant SOC 2 Trust Services Criteria — 66 of 68 controls are currently assessed compliant; the remaining two are physical-security controls inherited from our underlying cloud provider. Customers in healthcare-adjacent practice should request the BAA during the contract phase and walk through the Risk Register with our Security Officer.
What backups exist and how do you prove they work?
Managed cloud service: a managed relational database with 30-day point-in-time restore, soft-delete and versioning on object storage (14 days), and soft-delete + purge protection on the secret vault. Our most recent disaster-recovery restore drill was executed against production backups on 2026-05-28; the report is available in the Trust Center. Recovery objectives are RPO 1 hour, RTO 4 hours. Self-hosted: the same baseline templates ship with the deployment; your firm tunes retention to its own standards.
What happens during a security incident?
Our Incident Response Policy defines SEV-1/SEV-2/SEV-3 severities and binding response SLAs (SEV-1 24/7, SEV-2 within 2 hours, SEV-3 next business day). Customers affected by an incident touching their data are notified without undue delay and no later than 72 hours after confirmation. A written post-incident review is produced for every SEV-1 and SEV-2 within 5 business days. In self-hosted, your IR team owns the response and AtlasAI provides forensic support under contract; your SIEM has full visibility from the start.
How often is the platform pen-tested?
Independent third-party penetration testing happens at least annually and after any material change to the platform architecture. We also welcome customer-led penetration testing under coordinated rules of engagement. Continuous vulnerability detection runs at three layers: cloud-posture monitoring across infrastructure, dependency scanning on every pull request, and runtime threat detection on the application tier — with findings triaged against the SLAs defined in our Vulnerability Management Policy.
What documents can we get under NDA right now?
The full Atlas AI Security & Compliance Posture Report (live SOC 2 + HITRUST control matrix, architecture, sub-processors, incident response, audit roadmap, founder signature), plus 12 corporate policies (Information Security, Access Control, Change Management, Incident Response, BCP/DR, Vendor Management, Data Classification, Encryption, Vulnerability Management, SDLC, AUP, HR Security) and dated artifacts (Risk Register, Quarterly Access Review, DR Restore Drill Report, Workforce Training Record, Annual Security Program Review). Request access at app.atlas-ai.io/trust/request-access.
What happens to our data when we leave?
Customer data is retained for the duration of your subscription. On termination or written request, your data is deleted within 30 days of contract end. Backups containing the deleted data expire on their normal cycle (≤30 days for the database, ≤14 days for object storage) and are protected by all ordinary security controls during that window. We provide written confirmation of deletion. In self-hosted deployments, the entire stack lives inside your subscription — if you choose to walk away, you simply delete the resource group; nothing exits your tenant.

Built for the firms that
can’t afford to compromise

Walk through AtlasAI’s architecture with your security team. We’ll show you exactly where your data lives, who can access it, and why the answer to both is “only you.”

Start Free Trial