[ SECURITY CONTROLS ]
Controls teams can evaluate.
Identity, access, auditability, and session controls available across the Atlas workspace.
Encryption
AES-256 at rest, TLS 1.3 in transit.
Multi-factor authentication
Per-user (TOTP / authenticator app or email OTP) and org-enforced (require all members).
Owners and admins can require MFA for every member of their organisation in Organisation → Security. Members who have not yet enrolled are walked through setup the next time they sign in.
Single sign-on (SSO)
Google Workspace, Microsoft / Entra ID, Okta, OneLogin, SAML 2.0.
Owners and admins declare their email domain + provider in Organisation → Security. When "Enforce" is on, password sign-in is blocked for that domain. Initial handshake is completed by the Pimlico team within one business day.
Role-based access control
Owner, Admin, Member, Viewer - four roles per organisation.
Viewer is read-only: cannot export, edit watchlists, invite members, or change settings. Intended for auditors, legal observers, or stakeholders pre-commitment. Role changes are audited.
Customer-visible audit log
Every organisation sees its own recent sensitive actions in Settings → Account activity.
Role changes, security-policy updates, data exports, and incident posts from the status page are recorded with actor, timestamp, and relevant details. Internal long-range audit trail is retained separately per our security policy.
Session management
Automatic 8-hour inactivity timeout; active session revocation available via support.
For the full technical detail - network architecture, logging, backup and recovery, key management - see our Security overview or request our Security Whitepaper at contact@pimlicosolutions.com.
Pimlico Solutions Limited · Registered in England & Wales, Company No. 16505294 · Last reviewed 13 July 2026.