Security
Your portfolio data never leaves your dedicated environment.
How Atrium enforces data isolation, access controls, and a full audit trail for every reconciliation run.
Infrastructure
Encryption, isolation, and access controls built into the data layer.
Encryption at rest
AES-256 for all data stored on Atrium infrastructure. Encryption keys are per-customer, not shared across accounts. Key rotation on a 90-day cycle.
Encryption in transit
TLS 1.3 enforced on all connections. Older protocol versions disabled. SFTP connections use SSH-2 with key-based authentication. Certificate pinning available on request for API integrations.
Data isolation
Each fund vehicle runs in a logically isolated environment. Position records, tapes, and reconciliation outputs for one vehicle are inaccessible to another, even within the same fund manager account.
Infrastructure location
Hosted on AWS us-east-1 (primary) and us-west-2 (failover). No data stored outside the United States. Backup retention 30 days with point-in-time recovery.
Access controls
Role-based access. Per-vehicle scope. No lateral movement.
Full read/write access across all vehicles in the account. Manages user provisioning, API keys, and notification routing. Only role that can add or remove data sources.
Read access to all reconciled position data and IC reports across assigned vehicles. Cannot modify field mapping schemas or covenant rules. View-only on reconciliation logs.
Read and write access to field mapping configuration and manual position entries for assigned vehicles. Cannot access vehicles outside their scope. Cannot export raw tape files.
IC report access only. No access to position records, tape files, or reconciliation logs. Scoped to specific vehicles. Intended for investment committee members who need report access without operational data.
Authentication
SSO via SAML 2.0 and OIDC. Password-based authentication enforced with 12-character minimum and MFA required on all accounts. Session tokens expire after 8 hours of inactivity.
MFA enforcement
TOTP and hardware key (FIDO2) supported. MFA bypass not available except through a documented IT admin procedure. All MFA changes logged with timestamp and IP.
Audit trail
Every reconciliation run has a full audit log.
Not just a summary: every tape delivery, field mapping decision, and position change is logged with the source record, timestamp, and the user or system that triggered it.
Tape delivery log
Every tape file received is logged with delivery timestamp, source system, file hash, and number of records parsed. Available for 30 days with point-in-time query.
Reconciliation audit
Each reconciliation run produces a log of all position changes, field exceptions, and covenant test results. Log records the position ID, the prior value, the new value, and the tape row that sourced the change.
User activity log
All user actions that modify configuration, add positions, or export data are logged with user ID, timestamp, and IP address. Available to Fund Admin role for 90 days.
Export for LP reporting
Reconciliation audit logs exportable as CSV for LP due diligence requests. Available on Manager and Platform plans.
Compliance direction
Current state and what we're working toward.
On Roadmap
SOC 2 Type II
Audit planned for Q4 2026. We're documenting controls and working with an independent auditor now. Existing clients will receive a copy of the report on completion.
In Place
Data Processing Agreement
A signed DPA is available to all clients. Covers data controller and processor obligations, sub-processors, and breach notification requirements. Provided on request or during onboarding.
In Place
Data residency
All data processed and stored in the United States (AWS us-east-1, us-west-2). No cross-border data transfer. Suitable for US-domiciled fund vehicles operating under standard fund LP agreements.
On Roadmap
Pen testing (third-party)
External penetration test scheduled for Q3 2026. Results summary shared with clients under NDA. Internal security review conducted quarterly using automated tooling.
For detailed security documentation or to schedule a security review call, contact [email protected].
Security documentation available on request.
DPA, sub-processor list, and infrastructure summary provided to all active evaluations.