Autonomy is only useful
if it is accountable
smartATOM is built to ISO 27001:2022 and SOC 2 control objectives. Certification is in progress — what follows is what the system actually does with your data today.
- ISO 27001:2022
- Information security management system
- SOC 2 Type II
- Security, availability, confidentiality
- GDPR & CCPA
- Data processing agreement available
- Multi-region failover
- Active-active with latency routing
Tenant data is pinned to a region when the organisation is created and routed there for the life of the account. Multi-region failover preserves availability without moving data across a regulatory boundary.
- US Eastus-east-1
- US Westus-west-2
- EU Westeu-west-1
- EU Centraleu-central-1
- APACap-southeast-2
- Indiaap-south-1
Isolation enforced by the database, not by remembering a WHERE clause.
Tenant isolation at the database
Every row carries an organisation id and PostgreSQL row-level security enforces it on the connection. A query that forgets its tenant filter returns nothing — isolation does not depend on application code remembering.
Hash-chained audit evidence
Each audit entry hashes the previous entry for its tenant. Altering history breaks every subsequent hash, which makes tampering detectable without trusting the database operator.
Envelope encryption
Connector credentials and MFA secrets are encrypted with per-tenant data keys, wrapped by a key-encryption key. On enterprise plans that KEK is customer-managed: revoke it and our access ends.
Authentication hardening
scrypt password hashing at OWASP parameters, constant-time verification, progressive lockout, strict rate limits on every auth endpoint, and no response that distinguishes a registered address from an unregistered one.
Regional data residency
Tenant data is pinned to a region at creation and routed there for the life of the account. Multi-region failover keeps availability without relocating data across a regulatory boundary.
Least-privilege agents
Agents declare their tools; anything undeclared is unreachable rather than merely discouraged. Irreversible actions require a human gate the agent cannot remove.
No training on your data
Customer content is never used for model training, fine-tuning or evaluation. Inference runs against zero-retention endpoints with prompt content excluded from provider logging.
Continuous verification
Automated accessibility and dependency scanning in CI, annual third-party penetration testing, and a public status page with incident history rather than a green light.
Service status
All systems operational- API
- 99.99%
- 30-day uptime
- Orchestration
- 99.98%
- 30-day uptime
- Connectors
- 99.95%
- 30-day uptime
- Last incident
- 41 days
- degraded SAP sync, 22 min
Incidents are posted within 15 minutes of detection and updated every 30 minutes until resolved. Post-incident reviews are published within five business days, including the ones where we were at fault.
Terms & processing
Data processing agreement
Standard contractual clauses, sub-processor list and breach-notification commitments. Signed before any production data moves.
Service level agreement
99.9% on Business, 99.99% multi-region on Enterprise, with service credits that apply automatically rather than on request.
Acceptable use
What agents may be pointed at, and the categories of automated decision we will not support regardless of configuration.
Data portability and exit
Full export of records, flow definitions and audit evidence in open formats, available for 90 days after termination.
Full documents are provided during procurement. Ask sales@smartatom.ai for the current versions.
Reporting a vulnerability
Send findings to security@smartatom.ai. We acknowledge within one business day, provide a remediation timeline within five, and we will not pursue legal action against good-faith research conducted under our disclosure policy.
Ready to build
smarter operations?
Join the organisations replacing manual operations with governed autonomy. Your first application is live today.
Operate smarter. Achieve more.
