Security & compliance

The controls behind the promises.

Our customers in finance and education have to answer to regulators and auditors for how customer data is handled and how automated decisions are made. This page lays out how AtomMatrix protects data, governs its AI, and keeps the platform running — so you can give those answers with confidence.

Data protection

Customer data, handled carefully

Encryption, isolation, and retention controls applied to the messages, calls, and records that pass through the platform.

ENCRYPTION

In transit & at rest

Traffic is encrypted in transit, and stored data is encrypted at rest, across the services that make up the platform.

ISOLATION

Tenant separation

Each customer's data and configuration are logically isolated, so one tenant's traffic and content never bleed into another's.

RESIDENCY

Regional handling

Where finance or education requirements demand it, data can be processed and stored in specific regions.

RETENTION

Retention you set

Configure how long message content, recordings, and logs are kept, and when they're purged.

MINIMIZATION

Only what's needed

Collect and retain the data a workflow actually requires, with sensitive fields maskable in logs and analytics.

PORTABILITY

Export & deletion

Retrieve or delete customer records on request to support privacy obligations.

Identity & access

The right people, the right permissions.

Access is scoped, logged, and revocable. Nobody — including us — should have more reach into your data than the job requires.

01

Role-based access

Grant permissions by role so people can configure only what they're responsible for.

02

Single sign-on

Connect your identity provider so access follows your existing joiner-mover-leaver process.

03

Least privilege

Default to the minimum access needed, with elevated actions gated and recorded.

04

Credential & key handling

API keys and secrets are stored securely, rotatable, and scoped to what each integration needs.

AI governance

Automation you can put your name on

Agents act on your behalf, so the controls around them matter as much as the model behind them.

GUARDRAILS

Per-tenant content policy

Define what agents can and can't say or do, tuned by industry and use case — not one blanket setting.

HUMAN REVIEW

People on the sensitive calls

Route high-value, ambiguous, or regulated decisions to a person before anything is finalized.

AUDIT

A record of what happened

Keep the events that matter — what an agent decided, which tool it called, what it sent — for review.

FALLBACK

Safe by default

When an agent is unsure or a step fails, it takes a safe path or escalates rather than improvising.

DATA IN PROMPTS

Controlled context

Control what customer data is exposed to a model, with masking and scoping where appropriate.

ISOLATION

Your data stays yours

Your content is used to serve your workflows — not to train shared models on your behalf.

Reliability

Secure and available aren't the same thing.

Uptime is part of security when a missed passcode locks a customer out. The platform is built to keep running through outages, spikes, and attacks.

01

Multi-region & failover

Workloads span regions with automatic failover, so a single zone's bad day doesn't take you down.

02

Carrier redundancy

Multiple carriers per market mean delivery keeps flowing when one provider degrades.

03

Edge protection

Web application firewall and rate controls guard the APIs against abuse and volumetric attacks.

04

Monitoring & response

Continuous monitoring and alerting so issues are caught and worked before they spread.

Compliance

Meeting you where your rules are

Communications and privacy rules differ by country, industry, and channel. We handle what we can and are straight about the rest.

PRIVACY

Privacy obligations

Controls to support privacy regimes like GDPR — consent, access, deletion, and regional processing.

MESSAGING RULES

Opt-out & consent

Built-in opt-out handling, suppression lists, and quiet-hours support to keep campaigns compliant.

REGISTRATION

Sender registration

Where a market requires sender ID or business registration, we handle what we can on your behalf.

INDUSTRY

Regulated sectors

Data residency, audit trails, and human review designed for finance and education requirements.

Need documentation? Requirements vary by industry and region, and so do the artifacts your team needs — data processing terms, security questionnaires, residency commitments, or audit support. Tell us what your compliance and procurement teams require and we'll walk through what we can provide for your deployment.

Questions?

Bring your security team.

We'd rather answer the hard questions early. Loop in your security and compliance stakeholders and we'll go through data flows, controls, and documentation.