Runs on infrastructure you control
Atlas runs on infrastructure you control, whether its managed, in your VPC, on-premises, or air-gapped.
Security and compliance documentation for Atlas and the credit stack. It covers deployment models, security controls, policies, and how to request audit documents.
Live from Vanta · last updated 17 September 2026
How Atlas runs inside the firm: where it sits, what leaves, and who can see what.
Atlas runs on infrastructure you control, whether its managed, in your VPC, on-premises, or air-gapped.
Atlas uses SSO against the directory you already run. Joiners, movers and leavers stay in that directory.
Agents hold no secrets. The connector brokers each access and uses it for one action. No credential is written into a prompt, a runbook, or a trace.
Prompts leave your boundary only when you route a task to a model provider. Those calls run under zero-retention terms. Traces, rules and evals never leave.
The barriers that govern the underlying work also govern the rules, evals and retrieval built on it. A rule taught on one side of a barrier is not visible on the other side.
Atlas encrypts data in transit and at rest. Vanta monitors both controls continuously. Only the roles that need key access have it.
Frameworks Constellation runs against in Vanta. Reports and status letters are in Resources.
SOC 2 (System and Organization Controls 2) is a compliance framework that evaluates an organization's information security practices. It's a must-have for building trust with stakeholders by demonstrating robust security measures. Ideal for SaaS companies and IT service providers, SOC 2 helps unlock business opportunities by assuring clients of your security posture.
73 controls, monitored continuously in Vanta. Each category shows a sample below.
We share gated documents on request, under NDA where required.
Information security policies (combined)
The written information security program in one document. It covers access control, cryptography, secure development, incident response, business continuity and data management.
Penetration-testing report
The most recent third-party penetration test of the platform.
SOC 2 Type II report
The SOC II Audit Status Letter & Report
Security questionnaire response
Send your own questionnaire, such as SIG, CAIQ, or a firm template. We complete it against the control set above.
Four ways to run Atlas. The boundary differs in each one. The identity and credential model does not.
Atlas runs in an AWS, Azure or GCP account you own. Your network policy and your logging apply.
Documents, traces, rules and evals stay in your account. We operate the software. You own the perimeter.
The harness runs on infrastructure inside your own estate. It sits alongside the tools the desk already uses.
No data is written to a Constellation datastore. Model calls are the only egress, and only when you route a task.
For environments that must stay disconnected. Lab scopes the install to that constraint.
The whole platform sits inside your boundary, not only inference. There is no egress.
Constellation operates the deployment. This is the fastest path to a first eval set, if a hosted control plane fits your policy.
We document the boundary at implementation. Zero-retention terms flow down to every model provider in the path.
Three things are the same in every mode. Identity comes from your IdP. The connector brokers credentials, and no agent holds them. What Atlas learns stays a firm model that you own and can export.
The questions security, general counsel and procurement ask first. The longer set is on the FAQ page.
Deployment
On infrastructure you control, either locally or in your VPC. Atlas is not multi-tenant, and it does not train on your traces. Air-gapped installs are available for clients that need them.
Only prompts to a model API, under zero-retention terms. They leave only when you route a task to that provider. Traces, rules and evals never leave.
Yes. Identity stays yours. Joiners, movers and leavers remain in the directory you already run.
Security
No. Credentials never enter model context. The connector brokers each access and uses it for one action. Nothing is written into the prompt.
The same barriers that govern the underlying work apply to rules, evals and retrieval. A rule taught on one side of a barrier is not visible on the other side.
Request it from the document library below, or write to security@constellationfinance.ai. We answer questionnaires from the same address.
Privacy
No. We never use your documents or traces to train a model for anyone else. Every model API runs under zero-retention terms. You may train on your own work, inside your own perimeter, when your evals support it.
Your traces and rules stay for as long as you keep the deployment. Provider APIs retain nothing. We keep no copy of our own.
You can export your rules, evals and any post-trained weights. Providers are interchangeable. The firm model moves with you.
Report a vulnerability in the platform, a connector, or this site to security@constellationfinance.ai. Include the affected surface, the steps to reproduce it, and the impact you observed. We agree remediation and disclosure timing with you in that thread.
Procurement questionnaires and anything not listed here: security@constellationfinance.ai.