[ TRUST CENTRE ]

Trust begins with clear evidence.

Atlas security, privacy, AI governance and availability evidence in one place. Built for teams evaluating the platform and the procurement reviewers supporting them.

Live service status

Platform status, incident history, and email subscriptions. Internal health probes update the status page automatically every 5 minutes.

pimlico.statuspage.io

Provider assurance

SOC 2 Type II

Critical infrastructure providers maintain current reports

Privacy

UK & EU GDPR

DPA, SCCs and sub-processor details available for review

Pimlico SOC 2

Assessment in progress

Progress letter available on request

Control framework

ISO 27001 alignment

Controls mapped to Annex A; certification is not currently held

[ ASSURANCE ]

Certification and compliance posture.

Infrastructure certifications are listed separately from Pimlico Solutions' own assessment and certification status. We do not present roadmap work as a completed audit.

Request procurement documents
In place

Infrastructure: SOC 2 Type II

Hosted on Supabase and Cloudflare, both covered by current SOC 2 Type II reports.

We rely on Supabase and Cloudflare for data storage and delivery. Both providers maintain current SOC 2 Type II reports through their trust centres.

In progress

Pimlico Solutions SOC 2 Type II

Assessment in progress.

We are undergoing our own SOC 2 Type II assessment. Request a progress letter and expected certification date via /contact.

In place

GDPR

UK GDPR controls, with EU GDPR obligations addressed where applicable.

Our Data Processing Agreement and Standard Contractual Clauses are available on request. Sub-processor and cross-border routes are documented below.

In progress

ISO 27001 control alignment

Certification is not currently held.

Information-security policies, controls and evidence are mapped against ISO 27001 Annex A as the assurance programme matures.

[ SECURITY CONTROLS ]

Controls teams can evaluate.

Identity, access, auditability, and session controls available across the Atlas workspace.

In place

Encryption

AES-256 at rest, TLS 1.3 in transit.

In place

Multi-factor authentication

Per-user (TOTP / authenticator app or email OTP) and org-enforced (require all members).

Owners and admins can require MFA for every member of their organisation in Organisation → Security. Members who have not yet enrolled are walked through setup the next time they sign in.

In place

Single sign-on (SSO)

Google Workspace, Microsoft / Entra ID, Okta, OneLogin, SAML 2.0.

Owners and admins declare their email domain + provider in Organisation → Security. When "Enforce" is on, password sign-in is blocked for that domain. Initial handshake is completed by the Pimlico team within one business day.

In place

Role-based access control

Owner, Admin, Member, Viewer - four roles per organisation.

Viewer is read-only: cannot export, edit watchlists, invite members, or change settings. Intended for auditors, legal observers, or stakeholders pre-commitment. Role changes are audited.

In place

Customer-visible audit log

Every organisation sees its own recent sensitive actions in Settings → Account activity.

Role changes, security-policy updates, data exports, and incident posts from the status page are recorded with actor, timestamp, and relevant details. Internal long-range audit trail is retained separately per our security policy.

In place

Session management

Automatic 8-hour inactivity timeout; active session revocation available via support.

For the full technical detail - network architecture, logging, backup and recovery, key management - see our Security overview or request our Security Whitepaper at contact@pimlicosolutions.com.

[ PRODUCT AI GOVERNANCE ]

Governed AI, visible controls.

Atlas uses governed agents to research, structure and route regulatory work. The source trail remains visible, review stays with the responsible user, and approved outputs retain their context as they move into the team's workflow.

Defined agent scope

Agents work from the question, markets and sources the user selects.

The run stays bounded to a defined task rather than acting as an open-ended decision maker.

Source-linked outputs

Governing material remains available beside AI-assisted analysis.

Teams can inspect the evidence, context and cited output before relying on or sharing the work.

Human review and approval

AI-assisted work is prepared for review, not silently published or actioned.

The responsible user retains ownership of approval, interpretation and the resulting decision.

Governed handoffs

Approved work can move into reports, portfolios and connected systems.

The output, source context and responsible handoff remain connected as work moves forward.

[ SERVICE COMMITMENTS ]

Availability, support, and incident response.

Target availability

99.5% monthly uptime across the Platform, Database, and API components, as measured on pimlico.statuspage.io. Enterprise contracts may include bespoke commitments (99.9% with service credits) by written agreement.

Read the full Service Level Agreement

Support response times

In-product chat: minutes during UK business hours, with a human taking over when the conversation needs it. Email contact@pimlicosolutions.com: one business day or better. Enterprise tiers include priority queue + named account manager.

Incident response

Personal data breaches are notified to controllers within 72 hours of confirmation (UK GDPR Art. 33). Service incidents are posted to pimlico.statuspage.io as they're detected. Subscribe to updates on the status page to receive real-time email alerts.

[ DATA ROUTING ]

Sub-processors and regions.

We use the following processors to operate Atlas. Where data crosses borders we rely on UK and EU Standard Contractual Clauses plus the provider's own transfer mechanisms. Changes to this list are notified by email 30 days in advance (sign up via the status page).

Providers used to operate Atlas, their purpose, and processing region
ProviderPurposeRegion and terms
SupabaseManaged data platform, authentication and edge servicesHosting and transfer details are documented in the DPA and sub-processor schedule.
CloudflareFrontend delivery (atlas.pimlicosolutions.com, pimlicosolutions.com)Global network; processing and transfer details are documented in the DPA.
AnthropicAI inference (chat, summarisation, analysis via Claude)United States. Per Anthropic API terms, inputs and outputs are not used to train their models. Abuse-monitoring retention per Anthropic’s published policy. DPA available on request.
OpenAIText embeddings for semantic searchUnited States. Per OpenAI API terms, API data is not used to train their models. Retention per OpenAI’s published policy. DPA available on request.
ResendTransactional email deliveryUnited States
StripePayment processingUnited States / European billing entity
Atlassian StatuspageHosted service-status pageUnited States

[ PROCUREMENT ]

Documents available on request.

Request the DPA, Security Whitepaper, SOC 2 progress letter, sub-processor list as a PDF, or penetration-test summary at contact@pimlicosolutions.com or through /contact.

Data Processing Agreement (DPA)

UK GDPR + EU GDPR compliant. Standard Contractual Clauses included for cross-border transfers. Request at contact@pimlicosolutions.com or via /contact.

Security Whitepaper

Network architecture, access controls, backup and recovery, key management, vulnerability management.

SOC 2 progress letter

Confirmation of scope, auditor, and expected report date.

Penetration-test summary

Redacted executive summary of our most recent third-party pen test.

[ SECURITY REPORTING ]

Report a security issue.

If you believe you've found a vulnerability, email contact@pimlicosolutions.com or use /contact. We acknowledge within 24 hours, triage within 72, and communicate fix timelines based on severity. We're happy to credit researchers on our security page if you want the recognition.

Email a security report

Pimlico Solutions Limited · Registered in England & Wales, Company No. 16505294 · Last reviewed 13 July 2026.