[ SECURITY ]

Security controls, clearly stated.

How Pimlico Solutions protects Atlas data, from infrastructure and access control to AI processing and incident response.

Last updated

13 July 2026

For certification status, sub-processors, procurement documents, and service commitments, use the Trust Centre.

Open the Trust Centre

Primary data storage

EU (Frankfurt)

Supabase eu-central-1

Encryption

TLS 1.3 + AES-256

In transit and at rest

Pimlico SOC 2

Assessment in progress

Supabase + Cloudflare maintain SOC 2 Type II reports

ISO 27001

Not certified

Formal certification on the 2026 roadmap

[ CONTROL OVERVIEW ]

The safeguards around Atlas.

A concise view of where data is hosted, how access is controlled, how AI providers process data, and what happens when an incident is identified.

Infrastructure

Hosted on Cloudflare (frontend / CDN) and Supabase (database, authentication, edge functions). Primary data storage is Supabase’s EU region in Frankfurt. Both providers maintain current SOC 2 Type II reports. Our own SOC 2 Type II assessment is in progress.

Encryption

TLS 1.3 in transit, AES-256 at rest. API keys and service-account credentials are stored in provider-managed encrypted secret stores and rotated periodically. Nothing sensitive is committed to source control.

Authentication and MFA

Supabase Auth with email/password, Google Workspace, and Microsoft Entra. Multi-factor authentication is available to every user (authenticator app or email OTP) and can be enforced organisation-wide by owners/admins in Organisation → Security. SSO via SAML 2.0, Okta, and OneLogin is available with domain enforcement.

Access control

Row-level security (RLS) policies isolate organisations at the database level. Four roles per organisation — Owner, Admin, Member, Viewer — with Viewer read-only and unable to export. Administrative access at Pimlico is limited to named team members and logged in the internal audit trail.

AI and data processing

AI features use Anthropic’s Claude models (chat, summarisation, analysis) and OpenAI’s text embeddings (semantic search). Under each provider’s current API terms, your prompts and outputs are not used to train their models. Both providers retain inference data for a short period for abuse monitoring per their published retention policies. Copies of each provider’s Data Processing Agreement are available on request at contact@pimlicosolutions.com. Chat conversations are scoped to your organisation and stored in the same EU database as the rest of your data.

Incident response

Service incidents are posted to pimlico.statuspage.io as they’re detected and updated through resolution. Personal-data breaches are notified to affected data controllers within 72 hours of confirmation (UK GDPR Art. 33). Security disclosures: contact@pimlicosolutions.com — we acknowledge within 24 hours and triage within 72.

Compliance

Committed to UK and EU GDPR. Internal information-security policies modelled on ISO 27001 Annex A controls; formal certification is on our 2026 roadmap. Administrative actions on the platform are audit-logged; organisations see their own actions in Settings → Account activity, and can export their personal data at any time via Settings → Privacy (GDPR Art. 20).

[ RESPONSIBLE DISCLOSURE ]

Report a vulnerability.

Email contact@pimlicosolutions.com or use /contact. Please include a proof-of-concept and the affected surface so we can reproduce it.

We acknowledge security disclosures within 24 hours and triage within 72.

Email a security report

Pimlico Solutions Limited · London, United Kingdom · Last updated 13 July 2026.