Vendor evaluation

Answers to the standard questionnaire

One page, for attaching to a security review. Every line restates what the Trust page already says, so the two cannot disagree — and where the honest answer is “not yet”, it says so.

In place
In progress
Does not happen
Security controls, their current status, and the detail behind each.
ControlStatusDetail
SOC 2 Type II In observationSOC 2 Type II: observation period 18 August to 18 November 2026
ISO/IEC 27001:2022 Audit underway118 of 118 controls passing
Independent penetration test Passed0 critical / high / medium findings
Tenant data isolation Enforced in the databaseRow-Level Security (RLS) enforced on every database table
Isolation from the consulting practice No accessAtlanticM&A consulting personnel have zero access to customer tenant data. Tenant isolation enforced at the database layer (PostgreSQL Row-Level Security), encryption-at-rest via AWS KMS envelope encryption, audit logging on every access. AtlanticM&A — Agentic Transformation OS is operationally separate from the consulting practice; the only shared element is the brand. Independent sponsors and IIM members can use the platform without concern that their pipeline, stakeholder maps, or synergy thesis is visible to the consulting team.
Encryption at rest AES-256AES-256 encryption at rest
Encryption in transit TLS 1.2+TLS 1.2+ for all connections
Model training on your data NeverNo model training on customer data
Authentication MFA, SSO, passkeysPassword, passwordless, and SSO sign-in options
Role-based access control Per projectMultiple permission levels per project
Audit logging Every API routeFull audit log across all API routes
Employee access to production IAM with MFAProduction access via IAM Identity Center with MFA. No SSH access to containers. ECS Exec for emergency debugging only, fully audited via CloudTrail.
Secrets management AWS Secrets ManagerAWS Secrets Manager for all credentials and API keys
Vulnerability management ContinuousAWS Inspector and GuardDuty monitor for vulnerabilities and threats. AWS WAF protects against OWASP Top 10. Critical patches applied promptly.
Incident response 72-hour notificationWe maintain an incident response process for security events. Customers are notified within 72 hours of any confirmed breach affecting their data.
Backup and recovery 35-day retentionAurora automated backups with 35-day retention and point-in-time recovery. Infrastructure redeployable from CDK code. Separate staging environment for pre-production validation.
Secure development Reviewed before mergeAll code is reviewed before merging. Automated CI/CD pipeline with separate build, migration, and deploy stages. Infrastructure defined as code (AWS CDK) and version-controlled.
Data retention and deletion Account lifetimeCustomer data is retained only while the account is active. After termination, data is available for export for 30 days, then permanently deleted.
Sub-processors PublishedWe carefully select infrastructure and service providers that maintain their own compliance certifications.
Data residency Single regionThe platform runs as independent regional cells. A tenant belongs to exactly one, and its data stays there: the cells are separate AWS accounts with separate databases and no replication between them.
International data transfers SCCs availableStandard Contractual Clauses (SCCs) available

Evidence for any line is available on request, including the penetration-test attestation letter, the Data Processing Agreement and the Article 30 processing register. Completed SIG, CAIQ and VSAQ questionnaires are available from the Trust page.

Back to the Trust page