Security

Your portfolio data never leaves your dedicated environment.

How Atrium enforces data isolation, access controls, and a full audit trail for every reconciliation run.

Infrastructure

Encryption, isolation, and access controls built into the data layer.

Encryption at rest

AES-256 for all data stored on Atrium infrastructure. Encryption keys are per-customer, not shared across accounts. Key rotation on a 90-day cycle.

Encryption in transit

TLS 1.3 enforced on all connections. Older protocol versions disabled. SFTP connections use SSH-2 with key-based authentication. Certificate pinning available on request for API integrations.

Data isolation

Each fund vehicle runs in a logically isolated environment. Position records, tapes, and reconciliation outputs for one vehicle are inaccessible to another, even within the same fund manager account.

Infrastructure location

Hosted on AWS us-east-1 (primary) and us-west-2 (failover). No data stored outside the United States. Backup retention 30 days with point-in-time recovery.

Atrium infrastructure diagram showing per-vehicle data isolation and encryption layers

Access controls

Role-based access. Per-vehicle scope. No lateral movement.

Fund Admin

Full read/write access across all vehicles in the account. Manages user provisioning, API keys, and notification routing. Only role that can add or remove data sources.

Portfolio Manager

Read access to all reconciled position data and IC reports across assigned vehicles. Cannot modify field mapping schemas or covenant rules. View-only on reconciliation logs.

Operations Analyst

Read and write access to field mapping configuration and manual position entries for assigned vehicles. Cannot access vehicles outside their scope. Cannot export raw tape files.

IC Read-Only

IC report access only. No access to position records, tape files, or reconciliation logs. Scoped to specific vehicles. Intended for investment committee members who need report access without operational data.

Authentication

SSO via SAML 2.0 and OIDC. Password-based authentication enforced with 12-character minimum and MFA required on all accounts. Session tokens expire after 8 hours of inactivity.

MFA enforcement

TOTP and hardware key (FIDO2) supported. MFA bypass not available except through a documented IT admin procedure. All MFA changes logged with timestamp and IP.

Audit trail

Every reconciliation run has a full audit log.

Not just a summary: every tape delivery, field mapping decision, and position change is logged with the source record, timestamp, and the user or system that triggered it.

Tape delivery log

Every tape file received is logged with delivery timestamp, source system, file hash, and number of records parsed. Available for 30 days with point-in-time query.

Reconciliation audit

Each reconciliation run produces a log of all position changes, field exceptions, and covenant test results. Log records the position ID, the prior value, the new value, and the tape row that sourced the change.

User activity log

All user actions that modify configuration, add positions, or export data are logged with user ID, timestamp, and IP address. Available to Fund Admin role for 90 days.

Export for LP reporting

Reconciliation audit logs exportable as CSV for LP due diligence requests. Available on Manager and Platform plans.

Compliance direction

Current state and what we're working toward.

On Roadmap

SOC 2 Type II

Audit planned for Q4 2026. We're documenting controls and working with an independent auditor now. Existing clients will receive a copy of the report on completion.

In Place

Data Processing Agreement

A signed DPA is available to all clients. Covers data controller and processor obligations, sub-processors, and breach notification requirements. Provided on request or during onboarding.

In Place

Data residency

All data processed and stored in the United States (AWS us-east-1, us-west-2). No cross-border data transfer. Suitable for US-domiciled fund vehicles operating under standard fund LP agreements.

On Roadmap

Pen testing (third-party)

External penetration test scheduled for Q3 2026. Results summary shared with clients under NDA. Internal security review conducted quarterly using automated tooling.

For detailed security documentation or to schedule a security review call, contact [email protected].

Security documentation available on request.

DPA, sub-processor list, and infrastructure summary provided to all active evaluations.