Security and compliance documentation for Atlas and the credit stack. It covers deployment models, security controls, policies, and how to request audit documents.
Live from Vanta · last updated 17 September 2026
We share gated documents on request, under NDA where required. Requests go to the security team. We usually reply within one business day.
Information security policies (combined)
The written information security program in one document. It covers access control, cryptography, secure development, incident response, business continuity and data management.
Penetration-testing report
The most recent third-party penetration test of the platform.
SOC 2 Type II report
The SOC II Audit Status Letter & Report
Security questionnaire response
Send your own questionnaire, such as SIG, CAIQ, or a firm template. We complete it against the control set above.
Data Processing Addendum
The DPA. It includes the zero-retention terms that bind every model provider in the path.
Engagement Letter
Vanta branded Engagement Letter
Need more than one? . Or write to security@constellationfinance.ai directly. We answer questionnaires, such as SIG, CAIQ, or your own template, from the same address.