Security

M&A data is among the most sensitive information a company handles. We built AtlanticM&A with enterprise-grade security from day one — not bolted on after the fact.

SOC 2 Type II — In Progress

We are actively working toward SOC 2 Type II certification. Our infrastructure providers already hold SOC 2 Type II reports, and our application-level controls are designed to meet the Trust Services Criteria for Security, Availability, and Confidentiality.

Infrastructure controls in place Access controls in place Encryption in place Formal audit planned

Independent Penetration Test — Passed

In Q3 2026, an independent third-party security firm completed a full penetration test of the platform. No critical, high, or medium-severity findings were identified. Every finding was remediated or formally risk-accepted, and each remediation was retested and validated. A summary attestation letter is available to customers on request under NDA.

0 critical / high / medium findings Independent third party Remediated & retested Attestation on request

AWS Partner Network Member

Atlantic M&A is a member of the AWS Partner Network on the Software Path (Validated). Our platform completed the AWS Foundational Technical Review, a Well-Architected assessment against AWS security, reliability, and operational-excellence best practices, with zero high-risk findings. The review is valid through July 2028.

AWS Partner Network Software Path: Validated 0 high-risk findings Review valid through 2028

Security Controls

Cloud-Hosted Infrastructure

All services run on Amazon Web Services with industry-leading physical and network security. AWS maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.

  • Containerized compute on AWS ECS Fargate in private VPC
  • Aurora Serverless v2 PostgreSQL 17 with 35-day backup retention
  • AI processing via AWS Bedrock
  • AWS WAF with DDoS protection, bot control, and rate limiting

Tenant Data Isolation

Every customer's data is strictly isolated at the database level. One tenant can never access another tenant's data, even in the event of an application-level vulnerability.

  • Row-Level Security (RLS) enforced on every database table
  • No shared data between tenants
  • Separate staging and production environments

Encryption

All data is encrypted in transit and at rest using industry-standard algorithms.

  • TLS 1.2+ for all connections
  • AES-256 encryption at rest
  • Encrypted database connections

Authentication & Access Control

Enterprise-grade authentication with multiple sign-in options and mandatory multi-factor authentication.

  • Password, passwordless, and SSO sign-in options
  • FIDO2 passkey support (biometric/hardware keys)
  • TOTP authenticator app support
  • Role-based access control

Secrets Management

Application secrets and API keys are never stored in code or environment files on disk.

  • AWS Secrets Manager for all credentials and API keys
  • Secrets injected at runtime via ECS task definitions
  • No secrets in source control or Docker images
  • Principle of least privilege for all IAM roles

AI Data Handling

Core AI analysis is powered by large language models via AWS Bedrock and stays within the AWS environment — never used to train models. The optional meeting-notetaker feature additionally uses a third-party sub-processor (Recall.ai) to record and transcribe meetings, processed in your region (US or EU/UK).

  • Core AI analysis within your AWS environment (AWS Bedrock)
  • No model training on customer data
  • AI suggestions require explicit human approval

Access Controls & Audit

Fine-grained role-based permissions ensure users only see and modify what they're authorized to.

  • Multiple permission levels per project
  • Read-only viewer and audit roles
  • Full audit log across all API routes
  • Account hold and read-only enforcement

International Data Transfers

For customers outside the United States, we ensure data transfers comply with applicable regulations.

  • Standard Contractual Clauses (SCCs) available
  • EU-U.S. Data Privacy Framework where applicable
  • Data Processing Agreements on request

Vendor Compliance

We carefully select infrastructure and service providers that maintain their own compliance certifications.

VendorCertifications
Amazon Web ServicesSOC 2 Type II, ISO 27001, FedRAMP, PCI DSS
Aurora PostgreSQL (AWS)SOC 2 Type II, ISO 27001, FedRAMP
AWS Bedrock (AI Inference)SOC 2 Type II, ISO 27001
Paddle (Payment Processor)PCI DSS Level 1
GitHub (Source Control)SOC 2 Type II

Our Security Practices

Secure Development

All code is reviewed before merging. Automated CI/CD pipeline with separate build, migration, and deploy stages. Infrastructure defined as code (AWS CDK) and version-controlled.

Incident Response

We maintain an incident response process for security events. Customers are notified within 72 hours of any confirmed breach affecting their data.

Employee Access

Production access via IAM Identity Center with MFA. No SSH access to containers. ECS Exec for emergency debugging only, fully audited via CloudTrail.

Data Retention

Customer data is retained only while the account is active. After termination, data is available for export for 30 days, then permanently deleted.

Vulnerability Management

AWS Inspector and GuardDuty monitor for vulnerabilities and threats. AWS WAF protects against OWASP Top 10. Critical patches applied promptly.

Business Continuity

Aurora automated backups with 35-day retention and point-in-time recovery. Infrastructure redeployable from CDK code. Separate staging environment for pre-production validation.

Security Enquiries

Need a security questionnaire completed (SIG, CAIQ, VSAQ), our penetration-test attestation letter (under NDA), or our Technical Security Addendum? Send us a message and we'll respond within one business day.