Trust & security

Your shop’s data stays your shop’s data.

Atmosteel connects fabricators and detailers without mixing their work. Here is how we keep each company separate, protected and in charge of its own information.

A clear line between companies

  • Every fabricator and detailing company is its own tenant. Each request is checked against your company before any data is read or written.
  • A fabricator cannot see a detailer’s files or data, and a detailer cannot see a fabricator’s. The only exception is what one company deliberately shares with the other on a project.
  • Search indexes and AI memory are kept per company too, with automated tests that check one company’s documents never show up for another.

Where your data lives

  • Hosted on Amazon Web Services in the US (Ohio, us-east-2): app servers, database, file storage and drawing text reading all stay in that region.
  • Database: managed PostgreSQL with automated daily backups kept for 7 days. It is not reachable from the internet, only from our app servers.
  • Files and drawings: Amazon S3 with all public access blocked; downloads use short-lived signed links.

Protection

  • All traffic is HTTPS, through Cloudflare and an AWS load balancer.
  • The database and stored files are encrypted at rest.
  • Passwords are stored as bcrypt hashes; we never see or store your actual password.
  • App secrets and API keys are kept in AWS Systems Manager, not in code.

AI and your data

  • Atmos, the built-in assistant, only reads data your company can already see, with the same permission checks as the rest of the app.
  • Requests go to Anthropic (Claude) and OpenAI through their business APIs. Neither provider uses API data to train its models by default.
  • Your chats, memory and company playbooks are private to your company.

You stay in control

  • Atmos proposes changes such as RFIs, milestones and to-dos. Nothing is saved until a person approves it, and admins can turn individual action types off.
  • Company owners set a monthly AI spending cap.
  • An admin activity log shows who asked Atmos what, what it changed and what it cost, with CSV export.

Access

  • Role-based permissions per team member: admins decide who can see quotes, pricing, invoicing and billing.
  • Teams can be split by office location.
  • Removing a team member ends their access to your company on their next page load.

Last reviewed October 2026. Questions about security? Ask your Atmosteel contact.