Vendor evaluation
Answers to the standard questionnaire
One page, for attaching to a security review. Every line restates what the Trust page already says, so the two cannot disagree — and where the honest answer is “not yet”, it says so.
- In place
- In progress
- Does not happen
| Control | Status | Detail |
|---|---|---|
| SOC 2 Type II | In observation | SOC 2 Type II: observation period 18 August to 18 November 2026 |
| ISO/IEC 27001:2022 | Audit underway | 118 of 118 controls passing |
| Independent penetration test | Passed | 0 critical / high / medium findings |
| Tenant data isolation | Enforced in the database | Row-Level Security (RLS) enforced on every database table |
| Isolation from the consulting practice | No access | AtlanticM&A consulting personnel have zero access to customer tenant data. Tenant isolation enforced at the database layer (PostgreSQL Row-Level Security), encryption-at-rest via AWS KMS envelope encryption, audit logging on every access. AtlanticM&A — Agentic Transformation OS is operationally separate from the consulting practice; the only shared element is the brand. Independent sponsors and IIM members can use the platform without concern that their pipeline, stakeholder maps, or synergy thesis is visible to the consulting team. |
| Encryption at rest | AES-256 | AES-256 encryption at rest |
| Encryption in transit | TLS 1.2+ | TLS 1.2+ for all connections |
| Model training on your data | Never | No model training on customer data |
| Authentication | MFA, SSO, passkeys | Password, passwordless, and SSO sign-in options |
| Role-based access control | Per project | Multiple permission levels per project |
| Audit logging | Every API route | Full audit log across all API routes |
| Employee access to production | IAM with MFA | Production access via IAM Identity Center with MFA. No SSH access to containers. ECS Exec for emergency debugging only, fully audited via CloudTrail. |
| Secrets management | AWS Secrets Manager | AWS Secrets Manager for all credentials and API keys |
| Vulnerability management | Continuous | AWS Inspector and GuardDuty monitor for vulnerabilities and threats. AWS WAF protects against OWASP Top 10. Critical patches applied promptly. |
| Incident response | 72-hour notification | We maintain an incident response process for security events. Customers are notified within 72 hours of any confirmed breach affecting their data. |
| Backup and recovery | 35-day retention | Aurora automated backups with 35-day retention and point-in-time recovery. Infrastructure redeployable from CDK code. Separate staging environment for pre-production validation. |
| Secure development | Reviewed before merge | All code is reviewed before merging. Automated CI/CD pipeline with separate build, migration, and deploy stages. Infrastructure defined as code (AWS CDK) and version-controlled. |
| Data retention and deletion | Account lifetime | Customer data is retained only while the account is active. After termination, data is available for export for 30 days, then permanently deleted. |
| Sub-processors | Published | We carefully select infrastructure and service providers that maintain their own compliance certifications. |
| Data residency | Single region | The platform runs as independent regional cells. A tenant belongs to exactly one, and its data stays there: the cells are separate AWS accounts with separate databases and no replication between them. |
| International data transfers | SCCs available | Standard Contractual Clauses (SCCs) available |
Evidence for any line is available on request, including the penetration-test attestation letter, the Data Processing Agreement and the Article 30 processing register. Completed SIG, CAIQ and VSAQ questionnaires are available from the Trust page.