Atmos ProAtmos Pro
Trust Center
Contact security

Atmos Pro

Atmos Pro is a hosted platform for managing Terraform and OpenTofu infrastructure with drift detection, deployment provenance, change governance, and audit logging. This portal contains our security and compliance documentation.

security@cloudposse.comPrivacy Policy

Purchasing Atmos Pro? Visit Procurement for vendor details, agreements, and payment options.

OverviewResourcesControlsSubprocessorsFAQUpdates

Compliance

SOC 2 Type I & II
In progress

Actively pursuing; the product is built to SOC 2 security principles.

GDPR
DPA Available

Privacy practices are designed to support GDPR requirements.

Controls

Infrastructure security
No standing access to customer infrastructure clouds
Short-lived cloud credentials for your pipelines (OIDC/STS)
Least-privilege GitHub App scopes
View 12 more Infrastructure security controls
Organizational security
Multi-factor authentication enforced
Least-privilege internal access
Onboarding and offboarding procedures
View 7 more Organizational security controls
Product security
Mandatory peer code review
Dependency scanning
Secret scanning
View 8 more Product security controls
Internal security procedures
Incident response process
Public security bulletins
Logging and monitoring
View 12 more Internal security procedures controls
Data and privacy
Workspace data isolation
Data retention procedures established
Customer data deleted upon leaving
View 4 more Data and privacy controls