Security and Compliance
Complete guide to Atlan's security features, compliance certifications, and data protection capabilities.
Do you support HIPAA?
Yes, Atlan is HIPAA compliant. Visit Atlan's security portal to view the attestation letter from an external auditor.
Do you support SOC 2?
Yes, Atlan maintains SOC 2 Type II compliance certification. Visit Atlan's security portal to access compliance documentation and reports.
How does Atlan protect the data at rest?
Atlan implements comprehensive data protection measures. For detailed information, see Encryption and key management.
How's security enforced in Atlan?
Atlan uses Kubernetes in an Atlan-managed VPC (virtual private cloud). The data in Atlan is secured in the following ways:
- Infrastructure security: Restrict network access to the control planes as well as nodes.
- Access policies: Administrators can restrict user access to certain assets.
- Bring your own credentials (BYOC): Users can provide their own data store credentials to query data.
What data is Atlan actually bringing in?
Atlan enables you to search and discover metadata, not the data itself.
As a data catalog of all your data assets, Atlan enables you to:
- Extract metadata from source systems via pushdown queries or API requests.
- Process data with the sample data and query features, both of which can be turned off.
- Push down queries when sample data or query functionality is used, so, the results are neither cached nor stored in Atlan.
- Integrate with your supported data sources via a service account with read-only permissions to the data source and complete control over these permissions.
What Atlan IP address can I add to my organization's firewall?
If your organization's firewall only allows access from whitelisted IP locations, you can contact Atlan support to provide you with your Atlan IP address.