M&A data is among the most sensitive information a company handles. We built AtlanticM&A with enterprise-grade security from day one — not bolted on after the fact.
We are actively working toward SOC 2 Type II certification. Our infrastructure providers already hold SOC 2 Type II reports, and our application-level controls are designed to meet the Trust Services Criteria for Security, Availability, and Confidentiality.
In Q3 2026, an independent third-party security firm completed a full penetration test of the platform. No critical, high, or medium-severity findings were identified. Every finding was remediated or formally risk-accepted, and each remediation was retested and validated. A summary attestation letter is available to customers on request under NDA.
Atlantic M&A is a member of the AWS Partner Network on the Software Path (Validated). Our platform completed the AWS Foundational Technical Review, a Well-Architected assessment against AWS security, reliability, and operational-excellence best practices, with zero high-risk findings. The review is valid through July 2028.
All services run on Amazon Web Services with industry-leading physical and network security. AWS maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.
Every customer's data is strictly isolated at the database level. One tenant can never access another tenant's data, even in the event of an application-level vulnerability.
All data is encrypted in transit and at rest using industry-standard algorithms.
Enterprise-grade authentication with multiple sign-in options and mandatory multi-factor authentication.
Application secrets and API keys are never stored in code or environment files on disk.
Core AI analysis is powered by large language models via AWS Bedrock and stays within the AWS environment — never used to train models. The optional meeting-notetaker feature additionally uses a third-party sub-processor (Recall.ai) to record and transcribe meetings, processed in your region (US or EU/UK).
Fine-grained role-based permissions ensure users only see and modify what they're authorized to.
For customers outside the United States, we ensure data transfers comply with applicable regulations.
We carefully select infrastructure and service providers that maintain their own compliance certifications.
| Vendor | Certifications |
|---|---|
| Amazon Web Services | SOC 2 Type II, ISO 27001, FedRAMP, PCI DSS |
| Aurora PostgreSQL (AWS) | SOC 2 Type II, ISO 27001, FedRAMP |
| AWS Bedrock (AI Inference) | SOC 2 Type II, ISO 27001 |
| Paddle (Payment Processor) | PCI DSS Level 1 |
| GitHub (Source Control) | SOC 2 Type II |
All code is reviewed before merging. Automated CI/CD pipeline with separate build, migration, and deploy stages. Infrastructure defined as code (AWS CDK) and version-controlled.
We maintain an incident response process for security events. Customers are notified within 72 hours of any confirmed breach affecting their data.
Production access via IAM Identity Center with MFA. No SSH access to containers. ECS Exec for emergency debugging only, fully audited via CloudTrail.
Customer data is retained only while the account is active. After termination, data is available for export for 30 days, then permanently deleted.
AWS Inspector and GuardDuty monitor for vulnerabilities and threats. AWS WAF protects against OWASP Top 10. Critical patches applied promptly.
Aurora automated backups with 35-day retention and point-in-time recovery. Infrastructure redeployable from CDK code. Separate staging environment for pre-production validation.
Need a security questionnaire completed (SIG, CAIQ, VSAQ), our penetration-test attestation letter (under NDA), or our Technical Security Addendum? Send us a message and we'll respond within one business day.