Atmos Pro
Atmos Pro is a hosted platform for managing Terraform and OpenTofu infrastructure with drift detection, deployment provenance, change governance, and audit logging. This portal contains our security and compliance documentation.
Purchasing Atmos Pro? Visit Procurement for vendor details, agreements, and payment options.
Added backup and disaster-recovery detail to BC/DR control and whitepaper
Specified that the production database (Neon-managed PostgreSQL) has continuous point-in-time recovery and deletion protection enabled, with backups encrypted at rest in AWS us-east-1 (US) and containing only operational metadata — never customer source code or infrastructure state.
Corrected incident response control and whitepaper language
Our incident response control and whitepaper previously read as a fully documented process. Detection (Sentry, Vercel WAF, audit logs), an intake channel (security@cloudposse.com), and public incident communication are real and live today, but a written runbook defining severity levels, roles, and response timelines doesn't exist yet — that's in development.
Enabled merge-blocking SAST, SCA, and secrets-scanning gate
Semgrep (SAST), Trivy (SCA), Gitleaks, and Chainguard Malcontent Critical/High findings, or any detected secret, now block merges to main via required status checks.
Refreshed offboarding checklist and data-retention control language
Our offboarding checklist exists but had gone stale from infrequent use, so we described it as out of date and being refreshed rather than as a fully current, actively maintained process. Also scoped the data-retention control description to what's actually automated today.
Added support access, personnel confidentiality, and DPA disclosures
Published new controls and FAQ entries covering the read-only customer-gated support access model, personnel confidentiality agreements, and DPA availability.
Published Data Flow & Trust Boundaries diagram
Added an interactive trust-boundary diagram and a numbered data-flow table to Resources, mapping how data moves between your browser, Atmos Pro, GitHub, and your own cloud.
Trust Center gated to Business/Enterprise plans
Simplified the access-request workflow for gated Trust Center documents.
Trust Center launched
Published the Atmos Pro Trust Center with security and compliance documentation, control checklists across five areas (infrastructure, organizational, product, internal procedures, and data & privacy), a procurement FAQ, and a document request-access workflow.
Published Security Whitepaper
Published the Atmos Pro Security Architecture Whitepaper covering trust boundaries, the GitHub-only integration model, webhook security, encryption, audit logging, and data retention.
GitHub Enterprise Managed Users (EMU) support
Added support for GitHub Enterprise Managed Users (EMU) organizations, so customers on GitHub EMU can install and use Atmos Pro.