We use cookies to improve your experience and for marketing. View our Cookie Policy for more information.

Security and Compliance at Atlar

Author
Linda Wahlberg
Published
January 22, 2026
Last Update
September 3, 2026

Key takeaways

  1. Atlar is ISO 27001:2022 certified and SOC 2 Type 2 compliant, with full documentation available in its Trust Center.
  2. A SOC 2 Type 2 report evaluates whether controls work consistently over six to twelve months, not only whether they are designed correctly at a single point in time.
  3. Atlar operates on a zero-trust model, runs on Amazon Web Services in Europe, uses network segmentation and encryption at rest and in transit, scans for vulnerabilities continuously, and staffs a security team to respond around the clock.
  4. Platform controls include role-based access, approval chains for sensitive actions such as payments, SAML 2.0 SSO with providers including Google Workspace, Microsoft Entra ID, Okta, and AWS IAM Identity Center, MFA on login and sensitive operations, and complete audit trails.
  5. Atlar Intelligence is held to the same standards: customer data is never used to train models, processing runs on AWS in Europe, and the assistant can only surface information the user already has permission to access.

When finance teams choose a treasury platform, particularly one with AI built in, they're choosing a partner to trust with some of the most sensitive data in the organization. Companies like Mangopay, Tide, Trustly, and Zilch have stringent security requirements, and earning their trust means independently verified controls that hold up to scrutiny.

Atlar is both ISO 27001:2022 certified and SOC 2 Type 2 compliant. Our Trust Center has the full documentation.

Why SOC 2 Type 2 matters

For finance and IT teams evaluating vendors, SOC 2 (System and Organization Controls 2) compliance is often a baseline expectation. The distinction worth noting is between Type 1 and Type 2: a Type 1 report assesses whether controls are designed appropriately at a single point in time, while a Type 2 report evaluates whether those controls actually work, consistently, over six to twelve months.

In practical terms, our SOC 2 Type 2 report means an independent auditor has examined how we protect your data—and confirmed we do what we say we do.

How we approach security

We operate on a zero-trust model—no location is treated as inherently trusted, including our own office. Atlar runs on Amazon Web Services in Europe, with strict network segmentation and encryption at rest and in transit. Vulnerability scanning runs continuously, and our security team is staffed to respond to incidents around the clock.

Our security hub has more detail, and you can check real-time platform status on our status page.

Atlar supports approval chains configured to match your internal policies

Security features in the platform

The Atlar platform also gives customers direct control over their own security posture:

  • Role-based access control (RBAC). Assign permissions by job function so users can access only what they need.
  • Approval chains. Require multi-step sign-off on sensitive actions—particularly payments—configured to match your internal policies.
  • Single sign-on (SSO). SAML 2.0-based SSO with Google Workspace, Microsoft Entra ID, Okta, AWS IAM Identity Center, and others.
  • Multi-factor authentication (MFA). Enforce MFA at login and on sensitive operations like payment approvals.
  • Audit trails. Complete logs of every user and system action, always available for review.

AI with the same safeguards

Atlar Intelligence, the AI layer embedded across the platform, is held to the same security standards as everything else. Customer data is never used to train models. All processing runs on AWS in Europe, so your data never leaves Atlar's environment. And the assistant can only surface information that the user already has permission to access.

In short: the AI is designed to be useful without compromising the trust you've placed in us.

Atlar Intelligence provides answers grounded in your live treasury data

Certifications and regulatory alignment

Atlar's certifications and controls:

  • ISO 27001:2022. The international standard for information security management.
  • SOC 2 Type 2. Independent verification that our controls work over time.
  • GDPR. Data protection practices aligned with European regulations.
  • DORA. Controls aligned with EU requirements for financial sector resilience.

We also commission external penetration testing annually.

Questions?

If you'd like to discuss our security practices or need specific documentation for a vendor review, our team is happy to help.

Linda Wahlberg
Linda works closely with the product team to produce detailed, technical guides focused on cross-entity cash management for growing finance teams.

Frequently asked questions

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report assesses whether controls are designed appropriately at a single point in time. A Type 2 report evaluates whether those controls actually work, consistently, over six to twelve months. Atlar’s Type 2 report means an independent auditor has examined how data is protected and confirmed the stated controls operate over time.

Where does Atlar run, and what is the security model?

Atlar operates on a zero-trust model, so no location is treated as inherently trusted, including its own office. The platform runs on Amazon Web Services in Europe, with strict network segmentation and encryption at rest and in transit. Vulnerability scanning runs continuously, and the security team is staffed to respond to incidents around the clock.

What security controls can customers configure in the platform?

Customers can assign permissions with role-based access control so users access only what they need. Approval chains can require multi-step sign-off on sensitive actions, particularly payments, matching internal policies. SSO is SAML 2.0-based with Google Workspace, Microsoft Entra ID, Okta, AWS IAM Identity Center, and others. MFA can be enforced at login and on sensitive operations such as payment approvals, and complete audit logs of every user and system action are always available.

How is Atlar Intelligence handled from a security standpoint?

The AI layer is held to the same security standards as the rest of the platform. Customer data is never used to train models. All processing runs on AWS in Europe, so data does not leave Atlar’s environment. The assistant can only surface information that the user already has permission to access.

Which certifications and regulatory alignments does Atlar cite?

Atlar lists ISO 27001:2022 for information security management, SOC 2 Type 2 for independent verification of controls over time, GDPR-aligned data protection practices, and DORA-aligned controls for EU financial-sector resilience. It also commissions external penetration testing annually. Full documentation is in the Trust Center.

Get fresh insights, monthly.

You can unsubscribe anytime.

Read more

September 3, 2026
Product News

Atlar is Now Official in Claude

Atlar is now available in the Claude app directory. Any customer can connect Claude to Atlar and query their accounts, balances, transactions, or forecasts.

June 9, 2026
Product News

Bring Atlar into Claude

Atlar is now available in the Claude app directory. Any customer can connect Claude to Atlar and query their accounts, balances, transactions, or forecasts.

April 23, 2026
Product News

New in Atlar: Deeper Forecasting, Dark Mode, and FX Providers

What's new in Atlar: deeper forecasting, FX providers, payment schedules, dark mode, and improvements across the platform.

See Atlar in action.

Enter your work email to watch a live product demo.

Work Email
Phone Number (Optional)
Thanks, you will receive an invite email soon.
Oops, something went wrong. Try again with your work email.