Atlas HR Trust Center

Security, privacy, and AI boundaries for HR teams.

HR systems hold sensitive employee data. Atlas HR treats access control, auditability, privacy, responsible AI, and regional compliance as core product requirements rather than procurement afterthoughts.

Employee data protection

Atlas HR is designed around workspace membership, role-based permissions, service-role separation, and secure handling of employee records, documents, leave, payroll, performance, and case data.

AI with human review

Atlas AI assists with HR drafting, research, compliance review, and workflow guidance. It should not replace qualified HR, legal, payroll, tax, or employment counsel for high-risk decisions.

Audit-ready workflows

The platform includes audit log foundations, workflow records, approval states, document history, and admin controls so HR decisions can be reviewed later.

Regional compliance awareness

Atlas HR supports country-aware content and workflows for Nigeria, India, the UK, and the US, with review notes and counsel checkpoints where local rules matter.

Current controls

What Atlas HR already has in place.

These controls are product and codebase foundations. Formal security certifications, legal review, and procurement documents should be completed before enterprise launch.

Managed authentication controls
Role-based workspace access
Row-level security policies for org data
Audit logs for admin-sensitive activity
Webhook signature verification for payments
Cookie consent and privacy controls
Document retention and deletion foundations
AI legal-review warnings for high-risk answers

Responsible AI

Atlas AI is an assistant, not the final decision maker.

AI output can be incomplete, outdated, or jurisdiction-sensitive. Atlas HR should keep human approval, source review, and legal escalation visible in document generation, compliance answers, employee relations, and termination workflows.

Trust roadmap

What to finish before serious enterprise selling.

  • SOC 2 readiness evidence pack
  • Customer-facing data export and deletion request workflow
  • AI prompt/data retention disclosure by feature
  • Security questionnaire download for procurement
  • Incident status and breach communication runbook

Data protection

How Atlas HR protects customer data.

Atlas HR uses a limited set of vetted infrastructure, payments, email, analytics, and AI service providers under data-protection terms consistent with the GDPR. We do not publish the exact provider register publicly. Customers and procurement reviewers can request the current subprocessor list, regions, and transfer details under a DPA or appropriate review process.

Vetted providers support hosting, authentication, payments, email, analytics, and AI workflows.
Contractual safeguards, confidentiality duties, and access controls apply where providers process customer data.
Detailed provider, region, and transfer information is available to customers during procurement review.
Request a DPAProvider register available to customers on request.

Data residency

Primary application data is hosted with managed cloud infrastructure. Region-specific hosting can be arranged for enterprise engagements.

Encryption

Data is encrypted in transit (TLS). Sensitive integration secrets are encrypted at rest, and organisation data is governed by row-level security.

Retention

Workspace data is retained for the life of the account. Customers can request export or deletion; data is deleted or returned on termination per the DPA.

Breach notification

On a personal-data breach affecting Customer Data, Atlas HR notifies affected customers without undue delay, with the information needed to meet their own obligations.