Security at AtomicSam

    Your data powers your business. We treat its protection as a core product feature, not an afterthought.

    • Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
    • Hosted on enterprise-grade AWS infrastructure
    • Row-level security ensures data isolation between customers
    • Regular backups with point-in-time recovery
    • Secure authentication with password hashing and session management
    • We don't sell your data. Ever.

    AtomicSam runs on AWS-backed infrastructure via our platform providers. This gives us access to enterprise-grade physical security, network protection, and operational resilience without reinventing the wheel.

    Our infrastructure includes:

    • Geographically distributed data centres with redundancy
    • Automated failover and disaster recovery capabilities
    • DDoS protection at the network edge
    • Regular security patches and updates

    All data transmitted between your browser and AtomicSam is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and use modern cipher suites.

    Data stored in our databases and file storage is encrypted at rest using AES-256 encryption. Encryption keys are managed securely and rotated according to best practices.

    AtomicSam uses row-level security (RLS) to ensure strict data isolation between customers. This means:

    • Your data is only accessible to authenticated users within your organisation
    • Database queries are automatically scoped to your account
    • Even if a bug existed, the database enforces access rules at the lowest level

    We use industry-standard authentication practices:

    • Passwords are hashed using bcrypt with appropriate work factors
    • Sessions are managed securely with automatic expiry
    • Rate limiting protects against brute-force attacks
    • Role-based access controls let you manage permissions within your team

    We perform regular automated backups to protect against data loss:

    • Daily automated backups retained according to our retention policy
    • Point-in-time recovery available for database restoration
    • Backups are encrypted and stored in geographically separate locations

    We maintain visibility into our systems to detect and respond to issues:

    • Application and infrastructure monitoring for availability and performance
    • Security event logging for audit and investigation purposes
    • Alerting for anomalous activity or potential security events

    If a security incident occurs, we follow a structured response process:

    • Immediate containment and investigation
    • Root cause analysis and remediation
    • Notification to affected parties where required by law or appropriate in the circumstances
    • Post-incident review to prevent recurrence

    To report a security concern, contact privacy@atomicsam.com.

    We carefully select vendors and service providers who meet our security standards. Our key providers include:

    • Supabase (database, auth, storage) – SOC 2 Type II certified, built on AWS
    • Resend (email) – enterprise-grade email infrastructure
    • Google Analytics 4 – configured to minimise personal data collection

    AtomicSam is designed with privacy and compliance in mind:

    • Our infrastructure providers maintain SOC 2 Type II and ISO 27001 certifications
    • We follow GDPR principles for data handling and user rights
    • Our Privacy Policy details how we handle personal information

    If you need specific compliance documentation for vendor review, contact us and we'll provide what we can.

    Security is a shared responsibility. To keep your account secure, we recommend:

    • Use strong, unique passwords for your AtomicSam account
    • Don't share login credentials between team members
    • Review and remove access for team members who leave your organisation
    • Keep your devices and browsers up to date
    • Report suspicious activity to us promptly

    For security questions, concerns, or to report a vulnerability: privacy@atomicsam.com