Security you can verify.
How Salesjet and the ATOM Content Intelligence Platform protect customer data — the controls, the attestations, the people, and the playbooks behind the service.
Last updated: May 21, 2026
Security pillars
Encryption everywhere
All Customer Content is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher with modern cipher suites. Database backups and object storage are encrypted with managed keys rotated on the underlying provider's schedule.
Hardened hosting
Production workloads run on Cloudflare's global edge network and Supabase managed Postgres (AWS US regions, with EU residency available on enterprise plans). All providers maintain SOC 2 Type II and ISO 27001 attestations.
Least-privilege access
Employee access to production systems is gated by SSO with phishing-resistant MFA, scoped via role-based access control, audited continuously, and revoked within 24 hours of role change or termination.
Defense in depth
WAF, DDoS protection, bot mitigation, secret scanning, dependency scanning, static analysis, and runtime anomaly detection run on every commit and every request.
Independent testing
We engage a qualified third-party firm for an annual application and infrastructure penetration test. Continuous internal testing and bug-bounty-style researcher submissions supplement the annual engagement.
Monitoring and response
24x7 alerting on availability, error budgets, and security signals. Documented incident response playbooks with defined severity tiers, on-call rotation, and customer notification within 72 hours of confirmed personal-data breach.
Compliance & attestations
Current status of relevant frameworks. Audit reports, bridge letters, and questionnaire responses are available under NDA to qualified customers and prospects.
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Type II | In progress | Audit window opened Q2 2026. Report expected Q4 2026. Bridge letter available to customers under NDA on request. |
| GDPR | Compliant | EU Standard Contractual Clauses (2021/914) executed under our DPA. EU representative engaged for Article 27. |
| UK GDPR & Data Protection Act 2018 | Compliant | UK International Data Transfer Addendum executed under our DPA. |
| CCPA / CPRA | Compliant | Service-provider terms in our DPA. We do not sell or share personal information for cross-context behavioral advertising. |
| HIPAA | Not in scope | Salesjet is not a HIPAA Business Associate. Do not submit Protected Health Information. |
| PCI DSS | Out of scope (SAQ A) | All payment card data is handled by Stripe; Salesjet never stores card numbers. |
| ISO 27001 | Roadmap 2027 | Information Security Management System patterned on ISO 27001 controls; formal certification planned. |
Penetration testing
An independent third-party firm performs a black-box and grey-box penetration test of the application and supporting infrastructure on at least an annual cadence. High and critical findings are remediated before the engagement closes; medium and low findings are tracked to closure with documented SLAs. A summary letter is available to customers under NDA via security@atomauthority.com.
Vulnerability disclosure
We welcome reports from security researchers under a documented safe-harbor policy. Review our Vulnerability Disclosure Policy before testing, then submit findings to security@atomauthority.com. Our machine-readable security contact is published at /.well-known/security.txt (RFC 9116).
Sub-processors
The third parties we engage to deliver the Service are listed at /legal/subprocessors. Each operates under a written data-protection agreement consistent with our DPA.
Service status
Real-time availability, incident history, and scheduled maintenance are published at status.atomauthority.com (external status page — provider TBD; subscribe for email and webhook notifications once live).
Incident response
On confirmation of a security incident affecting Customer Content, we notify affected customers without undue delay and, in any event, within 72 hours of confirmation as required by GDPR Article 33. Notifications include known facts, suspected scope, mitigations taken, and recommended customer actions.
Security questionnaires
SIG, CAIQ, and custom questionnaires are returned within 5 business days for active opportunities.
security@atomauthority.comAudit reports
SOC 2 bridge letters and sub-processor attestations available under NDA.
legal@atomauthority.comReport a vulnerability
Researchers acting in good faith under our VDP receive safe harbor.
Read the policy