Help Center
Pages

Is Atlas SOC 2 and GDPR compliant?

Topic
Security & compliance
Asked by
Compliance and procurement teams
AdminUpdated Sep 11, 2026

Atlas is engineered to support your compliance obligations:

  • GDPR: built-in data-subject-request (DSR) tooling for access and erasure, user export/delete, encryption at rest, a full audit trail, and a Data Processing Agreement (DPA) available on Enterprise. Data residency can be pinned by region on Enterprise.

  • SOC 2 / general controls: encryption at rest, enforced tenant isolation, a partitioned tamper-evident audit log, granular access control (RBAC), rate limiting and account lockout give you the technical controls auditors look for. When you self-host, the operational controls are yours to attest to.

For the current list of formal attestations and to request our compliance documentation and DPA, please contact sales. We describe our security controls in detail in the security overview.

Atlas is built with the controls compliance programs require — encryption at rest, strict tenant isolation, a tamper-evident audit log, access controls and data-subject-request tooling. A DPA and data residency are available on Enterprise; contact us for current attestations.

Was this page helpful?
Is Atlas SOC 2 and GDPR compliant?