Security

M&A data is among the most sensitive information a company handles. We built AtlanticM&A with enterprise-grade security from day one — not bolted on after the fact.

SOC 2 Type II: observation period 18 August to 18 November 2026

Preparation and the internal audit are complete, and all 51 SOC 2 controls are passing. SOC 2 produces an attestation report rather than a certificate, and ours follows the close of the observation window on 18 November 2026. Until it is issued we have no report and will not imply otherwise. Our infrastructure providers already hold their own SOC 2 Type II reports.

Infrastructure controls in place Access controls in place Encryption in place Observation to 18 Nov 2026 51 of 51 controls passing

ISO/IEC 27001:2022: 118 of 118 controls passing, initial audit underway

All 118 controls are implemented and passing, preparation is complete and the internal audit is underway. Stage 1 and Stage 2 both sit ahead of a certificate, so we are not certified today and will say so until we are.

118 of 118 controls passing Monitored continuously Internal audit underwayNot yet certified

Independent Penetration Test — Passed

In Q3 2026, an independent third-party security firm completed a full penetration test of the platform. No critical, high, or medium-severity findings were identified. Every finding was remediated or formally risk-accepted, and each remediation was retested and validated. A summary attestation letter is available to customers on request under NDA.

0 critical / high / medium findings Independent third party Remediated & retested Attestation on request

AWS Partner Network Member

AtlanticM&A is a member of the AWS Partner Network on the Software Path (Validated). Our platform completed the AWS Foundational Technical Review, a Well-Architected assessment against AWS security, reliability, and operational-excellence best practices, with zero high-risk findings. The review is valid through July 2028.

AWS Partner Network Software Path: Validated 0 high-risk findings Review valid through 2028 AWS Qualified Software

Security Controls

Cloud-Hosted Infrastructure

All services run on Amazon Web Services with industry-leading physical and network security. AWS maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.

  • Containerized compute on AWS ECS Fargate in private VPC
  • Aurora Serverless v2 PostgreSQL 17 with 35-day backup retention
  • AI processing via AWS Bedrock
  • AWS WAF with DDoS protection, bot control, and rate limiting

Tenant Data Isolation

Every customer's data is strictly isolated at the database level. One tenant can never access another tenant's data, even in the event of an application-level vulnerability.

  • Row-Level Security (RLS) enforced on every database table
  • No shared data between tenants
  • Separate staging and production environments

Encryption

All data is encrypted in transit and at rest using industry-standard algorithms.

  • TLS 1.2+ for all connections
  • AES-256 encryption at rest
  • Encrypted database connections

Authentication & Access Control

Enterprise-grade authentication with multiple sign-in options and mandatory multi-factor authentication.

  • Password, passwordless, and SSO sign-in options
  • FIDO2 passkey support (biometric/hardware keys)
  • TOTP authenticator app support
  • Role-based access control

Secrets Management

Application secrets and API keys are never stored in code or environment files on disk.

  • AWS Secrets Manager for all credentials and API keys
  • Secrets injected at runtime via ECS task definitions
  • No secrets in source control or Docker images
  • Principle of least privilege for all IAM roles

AI Data Handling

Core AI analysis is powered by large language models via AWS Bedrock and stays within the AWS environment — never used to train models. The optional meeting-notetaker feature additionally uses a third-party sub-processor (Recall.ai) to record and transcribe meetings, processed in your region (US or EU/UK).

  • Core AI analysis within your AWS environment (AWS Bedrock)
  • No model training on customer data
  • AI suggestions require explicit human approval

Access Controls & Audit

Fine-grained role-based permissions ensure users only see and modify what they're authorized to.

  • Multiple permission levels per project
  • Read-only viewer and audit roles
  • Full audit log across all API routes
  • Account hold and read-only enforcement

Data Residency

The platform runs as independent regional cells. A tenant belongs to exactly one, and its data stays there: the cells are separate AWS accounts with separate databases and no replication between them.

  • US East (N. Virginia) and Europe (London) today
  • Your region is fixed when the account is created
  • Tell us before you sign up if you need a specific region; moving an existing tenant is a migration, not a setting

International Data Transfers

For customers outside the United States, we ensure data transfers comply with applicable regulations.

  • Standard Contractual Clauses (SCCs) available
  • EU-U.S. Data Privacy Framework where applicable
  • Data Processing Agreements on request

Vendor Compliance

We carefully select infrastructure and service providers that maintain their own compliance certifications.

VendorCertifications
Amazon Web ServicesSOC 2 Type II, ISO 27001, FedRAMP, PCI DSS
Aurora PostgreSQL (AWS)SOC 2 Type II, ISO 27001, FedRAMP
AWS Bedrock (AI Inference)SOC 2 Type II, ISO 27001
Paddle (Payment Processor)PCI DSS Level 1
GitHub (Source Control)SOC 2 Type II

Our Security Practices

Secure Development

All code is reviewed before merging. Automated CI/CD pipeline with separate build, migration, and deploy stages. Infrastructure defined as code (AWS CDK) and version-controlled.

Incident Response

We maintain an incident response process for security events. Customers are notified within 72 hours of any confirmed breach affecting their data.

Employee Access

Production access via IAM Identity Center with MFA. No SSH access to containers. ECS Exec for emergency debugging only, fully audited via CloudTrail.

Data Retention

Customer data is retained only while the account is active. After termination, data is available for export for 30 days, then permanently deleted.

Assistant Access You Control

If you connect an AI assistant to your account, you choose it, you choose what it may read, and you can disconnect it at any moment. Access is read-only, expires on a date you set, and stops immediately if your subscription lapses or the person who set it up leaves. We never select the assistant on your behalf.

Vulnerability Management

AWS Inspector and GuardDuty monitor for vulnerabilities and threats. AWS WAF protects against OWASP Top 10. Critical patches applied promptly.

Business Continuity

Aurora automated backups with 35-day retention and point-in-time recovery. Infrastructure redeployable from CDK code. Separate staging environment for pre-production validation.

Questions procurement asks

Are you SOC 2 certified?

Not yet, and the distinction matters. The Type II observation period runs 18 August to 18 November 2026, with infrastructure, access and encryption controls in place and monitored throughout. We will say "certified" when the report is issued, not before.

Has the platform been independently penetration tested?

Yes. An independent third party tested it and found zero critical, high or medium severity issues. Findings were remediated and retested. The attestation is available on request.

How is one customer's data kept separate from another's?

At the database level, not in application code. Row-Level Security is enforced on every table, so one tenant cannot reach another's data even if an application bug tried to. Staging and production are separate environments.

Is our data used to train AI models?

No. AI processing runs through AWS Bedrock, no model training is performed on customer data, and every AI suggestion requires explicit human approval before it changes anything.

What happens to our data if we leave?

It is retained only while the account is active. After termination it is available for export for 30 days, then permanently deleted.

Security Enquiries

Need a security questionnaire completed (SIG, CAIQ, VSAQ), our penetration-test attestation letter (under NDA), or our Technical Security Addendum? Send us a message and we'll respond within one business day.