Trust & Security

Security you can verify.

How Salesjet and the ATOM Content Intelligence Platform protect customer data — the controls, the attestations, the people, and the playbooks behind the service.

Last updated: May 21, 2026

Security pillars

  • Encryption everywhere

    All Customer Content is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher with modern cipher suites. Database backups and object storage are encrypted with managed keys rotated on the underlying provider's schedule.

  • Hardened hosting

    Production workloads run on Cloudflare's global edge network and Supabase managed Postgres (AWS US regions, with EU residency available on enterprise plans). All providers maintain SOC 2 Type II and ISO 27001 attestations.

  • Least-privilege access

    Employee access to production systems is gated by SSO with phishing-resistant MFA, scoped via role-based access control, audited continuously, and revoked within 24 hours of role change or termination.

  • Defense in depth

    WAF, DDoS protection, bot mitigation, secret scanning, dependency scanning, static analysis, and runtime anomaly detection run on every commit and every request.

  • Independent testing

    We engage a qualified third-party firm for an annual application and infrastructure penetration test. Continuous internal testing and bug-bounty-style researcher submissions supplement the annual engagement.

  • Monitoring and response

    24x7 alerting on availability, error budgets, and security signals. Documented incident response playbooks with defined severity tiers, on-call rotation, and customer notification within 72 hours of confirmed personal-data breach.

Compliance & attestations

Current status of relevant frameworks. Audit reports, bridge letters, and questionnaire responses are available under NDA to qualified customers and prospects.

FrameworkStatusDetail
SOC 2 Type IIIn progressAudit window opened Q2 2026. Report expected Q4 2026. Bridge letter available to customers under NDA on request.
GDPRCompliantEU Standard Contractual Clauses (2021/914) executed under our DPA. EU representative engaged for Article 27.
UK GDPR & Data Protection Act 2018CompliantUK International Data Transfer Addendum executed under our DPA.
CCPA / CPRACompliantService-provider terms in our DPA. We do not sell or share personal information for cross-context behavioral advertising.
HIPAANot in scopeSalesjet is not a HIPAA Business Associate. Do not submit Protected Health Information.
PCI DSSOut of scope (SAQ A)All payment card data is handled by Stripe; Salesjet never stores card numbers.
ISO 27001Roadmap 2027Information Security Management System patterned on ISO 27001 controls; formal certification planned.

Penetration testing

An independent third-party firm performs a black-box and grey-box penetration test of the application and supporting infrastructure on at least an annual cadence. High and critical findings are remediated before the engagement closes; medium and low findings are tracked to closure with documented SLAs. A summary letter is available to customers under NDA via security@atomauthority.com.

Vulnerability disclosure

We welcome reports from security researchers under a documented safe-harbor policy. Review our Vulnerability Disclosure Policy before testing, then submit findings to security@atomauthority.com. Our machine-readable security contact is published at /.well-known/security.txt (RFC 9116).

Sub-processors

The third parties we engage to deliver the Service are listed at /legal/subprocessors. Each operates under a written data-protection agreement consistent with our DPA.

Service status

Real-time availability, incident history, and scheduled maintenance are published at status.atomauthority.com (external status page — provider TBD; subscribe for email and webhook notifications once live).

Incident response

On confirmation of a security incident affecting Customer Content, we notify affected customers without undue delay and, in any event, within 72 hours of confirmation as required by GDPR Article 33. Notifications include known facts, suspected scope, mitigations taken, and recommended customer actions.

Security questionnaires

SIG, CAIQ, and custom questionnaires are returned within 5 business days for active opportunities.

security@atomauthority.com

Audit reports

SOC 2 bridge letters and sub-processor attestations available under NDA.

legal@atomauthority.com

Report a vulnerability

Researchers acting in good faith under our VDP receive safe harbor.

Read the policy