M&A data is among the most sensitive information a company handles. We built AtlanticM&A with enterprise-grade security from day one — not bolted on after the fact.
Preparation and the internal audit are complete, and all 51 SOC 2 controls are passing. SOC 2 produces an attestation report rather than a certificate, and ours follows the close of the observation window on 18 November 2026. Until it is issued we have no report and will not imply otherwise. Our infrastructure providers already hold their own SOC 2 Type II reports.
All 118 controls are implemented and passing, preparation is complete and the internal audit is underway. Stage 1 and Stage 2 both sit ahead of a certificate, so we are not certified today and will say so until we are.
In Q3 2026, an independent third-party security firm completed a full penetration test of the platform. No critical, high, or medium-severity findings were identified. Every finding was remediated or formally risk-accepted, and each remediation was retested and validated. A summary attestation letter is available to customers on request under NDA.
AtlanticM&A is a member of the AWS Partner Network on the Software Path (Validated). Our platform completed the AWS Foundational Technical Review, a Well-Architected assessment against AWS security, reliability, and operational-excellence best practices, with zero high-risk findings. The review is valid through July 2028.
All services run on Amazon Web Services with industry-leading physical and network security. AWS maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.
Every customer's data is strictly isolated at the database level. One tenant can never access another tenant's data, even in the event of an application-level vulnerability.
All data is encrypted in transit and at rest using industry-standard algorithms.
Enterprise-grade authentication with multiple sign-in options and mandatory multi-factor authentication.
Application secrets and API keys are never stored in code or environment files on disk.
Core AI analysis is powered by large language models via AWS Bedrock and stays within the AWS environment — never used to train models. The optional meeting-notetaker feature additionally uses a third-party sub-processor (Recall.ai) to record and transcribe meetings, processed in your region (US or EU/UK).
Fine-grained role-based permissions ensure users only see and modify what they're authorized to.
The platform runs as independent regional cells. A tenant belongs to exactly one, and its data stays there: the cells are separate AWS accounts with separate databases and no replication between them.
For customers outside the United States, we ensure data transfers comply with applicable regulations.
We carefully select infrastructure and service providers that maintain their own compliance certifications.
| Vendor | Certifications |
|---|---|
| Amazon Web Services | SOC 2 Type II, ISO 27001, FedRAMP, PCI DSS |
| Aurora PostgreSQL (AWS) | SOC 2 Type II, ISO 27001, FedRAMP |
| AWS Bedrock (AI Inference) | SOC 2 Type II, ISO 27001 |
| Paddle (Payment Processor) | PCI DSS Level 1 |
| GitHub (Source Control) | SOC 2 Type II |
All code is reviewed before merging. Automated CI/CD pipeline with separate build, migration, and deploy stages. Infrastructure defined as code (AWS CDK) and version-controlled.
We maintain an incident response process for security events. Customers are notified within 72 hours of any confirmed breach affecting their data.
Production access via IAM Identity Center with MFA. No SSH access to containers. ECS Exec for emergency debugging only, fully audited via CloudTrail.
Customer data is retained only while the account is active. After termination, data is available for export for 30 days, then permanently deleted.
If you connect an AI assistant to your account, you choose it, you choose what it may read, and you can disconnect it at any moment. Access is read-only, expires on a date you set, and stops immediately if your subscription lapses or the person who set it up leaves. We never select the assistant on your behalf.
AWS Inspector and GuardDuty monitor for vulnerabilities and threats. AWS WAF protects against OWASP Top 10. Critical patches applied promptly.
Aurora automated backups with 35-day retention and point-in-time recovery. Infrastructure redeployable from CDK code. Separate staging environment for pre-production validation.
Not yet, and the distinction matters. The Type II observation period runs 18 August to 18 November 2026, with infrastructure, access and encryption controls in place and monitored throughout. We will say "certified" when the report is issued, not before.
Yes. An independent third party tested it and found zero critical, high or medium severity issues. Findings were remediated and retested. The attestation is available on request.
At the database level, not in application code. Row-Level Security is enforced on every table, so one tenant cannot reach another's data even if an application bug tried to. Staging and production are separate environments.
No. AI processing runs through AWS Bedrock, no model training is performed on customer data, and every AI suggestion requires explicit human approval before it changes anything.
It is retained only while the account is active. After termination it is available for export for 30 days, then permanently deleted.
Need a security questionnaire completed (SIG, CAIQ, VSAQ), our penetration-test attestation letter (under NDA), or our Technical Security Addendum? Send us a message and we'll respond within one business day.