In transit & at rest
Traffic is encrypted in transit, and stored data is encrypted at rest, across the services that make up the platform.
Security & compliance
Our customers in finance and education have to answer to regulators and auditors for how customer data is handled and how automated decisions are made. This page lays out how AtomMatrix protects data, governs its AI, and keeps the platform running — so you can give those answers with confidence.
Data protection
Encryption, isolation, and retention controls applied to the messages, calls, and records that pass through the platform.
Traffic is encrypted in transit, and stored data is encrypted at rest, across the services that make up the platform.
Each customer's data and configuration are logically isolated, so one tenant's traffic and content never bleed into another's.
Where finance or education requirements demand it, data can be processed and stored in specific regions.
Configure how long message content, recordings, and logs are kept, and when they're purged.
Collect and retain the data a workflow actually requires, with sensitive fields maskable in logs and analytics.
Retrieve or delete customer records on request to support privacy obligations.
Identity & access
Access is scoped, logged, and revocable. Nobody — including us — should have more reach into your data than the job requires.
Grant permissions by role so people can configure only what they're responsible for.
Connect your identity provider so access follows your existing joiner-mover-leaver process.
Default to the minimum access needed, with elevated actions gated and recorded.
API keys and secrets are stored securely, rotatable, and scoped to what each integration needs.
AI governance
Agents act on your behalf, so the controls around them matter as much as the model behind them.
Define what agents can and can't say or do, tuned by industry and use case — not one blanket setting.
Route high-value, ambiguous, or regulated decisions to a person before anything is finalized.
Keep the events that matter — what an agent decided, which tool it called, what it sent — for review.
When an agent is unsure or a step fails, it takes a safe path or escalates rather than improvising.
Control what customer data is exposed to a model, with masking and scoping where appropriate.
Your content is used to serve your workflows — not to train shared models on your behalf.
Reliability
Uptime is part of security when a missed passcode locks a customer out. The platform is built to keep running through outages, spikes, and attacks.
Workloads span regions with automatic failover, so a single zone's bad day doesn't take you down.
Multiple carriers per market mean delivery keeps flowing when one provider degrades.
Web application firewall and rate controls guard the APIs against abuse and volumetric attacks.
Continuous monitoring and alerting so issues are caught and worked before they spread.
Compliance
Communications and privacy rules differ by country, industry, and channel. We handle what we can and are straight about the rest.
Controls to support privacy regimes like GDPR — consent, access, deletion, and regional processing.
Built-in opt-out handling, suppression lists, and quiet-hours support to keep campaigns compliant.
Where a market requires sender ID or business registration, we handle what we can on your behalf.
Data residency, audit trails, and human review designed for finance and education requirements.
Questions?
We'd rather answer the hard questions early. Loop in your security and compliance stakeholders and we'll go through data flows, controls, and documentation.
Review requirements for your industry and regions. Start a conversation →
How security fits into the architecture. Platform security →