Skip to main content

Compliance standards and assessments

Atlan adheres to various industry standards and regulations to ensure the security, privacy, and integrity of the platform. This entails conducting both external audits and internal assessments to continuously improve compliance standards.

Following is an overview of Atlan's key compliance certifications and internal assessment practices:

ComplianceDescriptionStatusFrequency
ISO 27001The Information Security Management System (ISMS) standard ensures data confidentiality, integrity, and availability.CertifiedAnnual
ISO 27701The Privacy Information Management System (PIMS) standard manages PII and ensures compliance with privacy regulations like GDPR and CCPA.CertifiedAnnual
ISO/IEC 42001:2023The AI Management System (AIMS) standard provides a framework for responsible development and use of AI systems. Audited by Prescient Security.CertifiedAnnual
SOC 2 Type IIThe SOC (System and Organization Controls) 2 Type II report attests to the security, availability, confidentiality, and privacy controls for service organizations.CertifiedAnnual
GDPRThe General Data Protection Regulation (GDPR) is an EU regulation that ensures the protection of personal data by enforcing strict privacy and security measures, along with giving individuals control over their data. Atlan adheres to GDPR through ongoing compliance, including breach notifications, data subject rights, and consent management.CertifiedAnnual
EU-U.S. Data Privacy FrameworkThe Data Privacy Framework outlines policies and controls that govern how Atlan handles personal information to ensure data protection and compliance with privacy regulations like GDPR.CompliantAnnual
EU AI ActThe EU AI Act establishes a risk-based regulatory framework for artificial intelligence systems operating in the EU. Atlan's ISO/IEC 42001:2023-certified AI Management System underpins alignment with these requirements.AlignedOngoing
HIPAAHIPAA, or the Health Insurance Portability and Accountability Act, safeguards protected health information (PHI).CompliantAnnual
VAPT assessmentsAnnual third-party Vulnerability Assessment and Penetration Testing (VAPT) assessments help identify and mitigate potential vulnerabilities within the Atlan platform.OngoingAnnual