We use cookies to improve your experience and for marketing. View our Cookie Policy for more information.

Securing Your Treasury With Atlar

Author
Joel Wägmark
Published
January 22, 2025
Last Update
September 22, 2026
Stack of layered blue shield icons representing security

Key takeaways

  1. Atlar complies with ISO 27001:2022 and has launched a Trust Center for certificates and details on security procedures supporting Treasury and Corporate IT policies.
  2. Infrastructure and applications are hosted on AWS in Europe, in a locked-down VPC within a single dedicated AWS account, with encryption at rest and in transit via AWS KMS.
  3. Atlar uses VPC Flow Logs, GuardDuty, AWS Shield, and WAF for monitoring and protection, plus Dependabot, AWS Security Hub, and threat intelligence feeds for vulnerability assessment.
  4. Platform controls include SAML 2.0 SSO with major identity providers, multi-factor authentication (including SWIFT 3SKey), role-based access control, customizable multi-step approval chains, and comprehensive audit trails.
  5. Certificates and reports available through the Trust Center include ISO 27001:2022, GDPR, DORA, and penetration tests.

Security is a priority for the entire Atlar team. Our customers entrust us with sensitive financial data, and we take that role seriously.

We continually evolve our security posture by complying with stringent certifications, like ISO 27001:2022, and enacting new product and organizational measures. This ensures that Atlar remains a safe partner to manage money with and delivers the reliability that our customers expect (you can see our status page here).

In line with this, we’re pleased to introduce our new Trust Center. This is where you can access our latest certificates plus detailed information on our security procedures and how we support your Treasury and Corporate IT policies. 

You can also find more information about our multi-layered approach in our security hub.

Security is core to the Atlar platform

How we support your organization

Our team

Atlar’s corporate and information security teams, staffed with experienced professionals, are geared to respond to possible security incidents 24/7 and are responsible for providing quick resolutions to security and privacy issues.

We proactively maintain and adapt a comprehensive set of security policies in order to ensure that security remains at the heart of everything we do, including:

  • Access management (zero-trust policy and principle of least privilege) 
  • Change management (including that all infrastructure is configured as code)
  • Secure coding practices
  • Company-wide security awareness and training

You can learn more about our approach to each of these areas here.

Hosting and network segmentation

Atlar hosts its infrastructure and applications on Amazon Web Services (AWS) in Europe. AWS allows Atlar to scale efficiently when it comes to performance and availability—and provides the strongest guarantee possible in terms of infrastructure security and reliability.

The Atlar platform runs in a locked-down virtual private cloud (VPC) within a single dedicated AWS account and employs the strictest possible access controls.

Encryption

Atlar uses strong encryption algorithms to protect data both at rest and in transit. We leverage AWS Key Management Service (KMS) in order to manage encryption keys in line with industry best practices.

Intrusion detection and prevention

Atlar utilizes AWS security programs, including VPC Flow Logs and GuardDuty, to monitor for and detect anomalous behavior. Additionally, Atlar uses AWS Shield and Web Application Firewall (WAF) to further protect the platform from potential threats and attacks.

Threat intelligence

Atlar uses internal and external scanning tools (including GitHub’s Dependabot and the AWS Security Hub) to continuously monitor and assess potential vulnerabilities. We also leverage threat intelligence feeds and industry security reports that deliver relevant information to us in real time.

‍

Platform features and capabilities

SAML-based Single Sign-On (SSO)

Single Sign-On allows users to log into Atlar within a customer’s internal security environment. With SSO, no additional usernames, IDs, or passwords are required and all access controls can be managed by our customers. Atlar employs SAML 2.0 for LDAP authentication and supports all major identity providers, including Google Workspace, Microsoft Entra ID, AWS IAM Identity Center, Okta, and JumpCloud. Learn more about SSO here.

Atlar supports SSO for all major identity providers

Multi-Factor Authentication

Multi-factor authentication (MFA) creates a randomly generated one-time password using the user’s smartphone, a token, or a SWIFT 3SKey digital certificate. When MFA is activated, the user is prompted to enter the one-time password after submitting their normal username and password—making it an effective fraud prevention tool when used on its own or, ideally, in combination with other Atlar security features. Learn more about secure authentication and the Atlar platform here.

User Management

The Atlar platform leverages role-based access control (RBAC) to ensure users have only the permissions required for their roles, adhering to the principle of least privilege. This minimizes the risk of unauthorized access and enhances overall security by strictly controlling user permissions and access levels.

Administrators can manage roles and permissions centrally, ensuring that security policies are consistently applied across the organization. More information can be found here.

Approval Chains

To enhance security around sensitive actions, the Atlar platform allows customers to create and enforce multi-step approval chains. This helps to reduce the risk of fraud and ensures that all actions, such as payments, are thoroughly vetted. These approval chains are fully customizable, allowing organizations to tailor them to their specific security requirements and policies.

Audit Trails

Atlar makes comprehensive audit trails available to its customers. These audit trails contain detailed records of all user and system activity that occurs, enabling administrators to undertake a granular review of all changes, operations, and events. This helps to ensure accountability within an organization, and can also facilitate security and incident-related investigations.

Atlar offers audit trails and user management tools

Assurances and compliance

Atlar maintains a number of certifications relating to security and compliance and also routinely engages external firms to conduct penetration testing and other forms of ethical hacking. You can access the following certificates and reports through our Trust Center:

  • ISO 27001:2022
  • General Data Protection Regulation (GDPR)
  • Digital Operational Resilience Act (DORA)
  • Penetration tests
Atlar is ISO 27001:2022 certified

Get in touch

If you have specific questions about any of our security policies or procedures, don’t hesitate to contact our team and we’ll be happy to help.

Joel Wägmark
Drawing on his background in payments at Tink, Joel leads product and finance at Atlar, building reliable, productized bank connectivity platforms.

Frequently asked questions

Where can customers review Atlar’s security certifications and procedures?

Atlar introduced a Trust Center for latest certificates and detailed information on security procedures and how it supports Treasury and Corporate IT policies. Further information on its multi-layered approach is also in its security hub. The Trust Center includes ISO 27001:2022, GDPR, DORA, and penetration test reports.

How does Atlar host and encrypt customer data?

Atlar hosts infrastructure and applications on Amazon Web Services in Europe. The platform runs in a locked-down virtual private cloud within a single dedicated AWS account with strict access controls. Data is encrypted at rest and in transit, with encryption keys managed through AWS Key Management Service (KMS).

What authentication and access controls does the Atlar platform provide?

Atlar supports SAML 2.0 single sign-on with identity providers including Google Workspace, Microsoft Entra ID, AWS IAM Identity Center, Okta, and JumpCloud, so access can be managed in the customer’s environment. Multi-factor authentication can use a smartphone one-time password, a token, or a SWIFT 3SKey digital certificate. Role-based access control limits users to the permissions required for their roles, following least privilege.

How does Atlar support payment security and accountability?

Customers can create and enforce customizable multi-step approval chains for sensitive actions such as payments, to reduce fraud risk and match internal policies. Comprehensive audit trails record user and system activity so administrators can review changes, operations, and events for accountability and investigations.

How does Atlar monitor threats and respond to incidents?

Corporate and information security teams are staffed to respond to possible security incidents 24/7. Atlar uses AWS VPC Flow Logs and GuardDuty to detect anomalous behavior, and AWS Shield and WAF to protect the platform. It also uses scanning tools including GitHub’s Dependabot and AWS Security Hub, plus threat intelligence feeds and industry security reports.

Get fresh insights, monthly.

You can unsubscribe anytime.

Read more

September 3, 2026
•
Product News

Atlar is Now Official in Claude

Atlar is now available in the Claude app directory. Any customer can connect Claude to Atlar and query their accounts, balances, transactions, or forecasts.

June 9, 2026
•
Product News

Bring Atlar into Claude

Atlar is now available in the Claude app directory. Any customer can connect Claude to Atlar and query their accounts, balances, transactions, or forecasts.

April 23, 2026
•
Product News

New in Atlar: Deeper Forecasting, Dark Mode, and FX Providers

What's new in Atlar: deeper forecasting, FX providers, payment schedules, dark mode, and improvements across the platform.

See Atlar in action.

Enter your work email to watch a live product demo.

Work Email
Phone Number (Optional)
Thanks, you will receive an invite email soon.
Oops, something went wrong. Try again with your work email.