Security & Data Protection

Your data never leaves your company.

Your revenue, your customer list, your employee records — all of it stays on your own computer.

Data stays inside the company building and never leaves
Data circulates inside your company. There is no path leading out.
🏠

Where does the data live?

On your own computer. It is not copied, uploaded or moved. The team that builds ATLAS has no access to your data.

🔒

What reaches the AI layer?

Raw records are never sent. Invoice lines, individual employee records and customer lists do not leave the premises. Only your question and the prepared summary figures are passed on.

📴

Local model option

If you prefer, the AI layer also runs entirely on your own machine. In that case nothing leaves at all — you do not even need an internet connection.

👥

Who sees what?

Role-based access. The production manager cannot see HR data; the operator sees only their own form.

🔑

Key security

If the cloud model is chosen, the API key lives on the server only; it is never embedded in the dashboard, the browser or the HTML.

📝

Audit trail

Who entered which data and when, and who viewed what, is recorded. It can be used for audit and accountability purposes.

Data protection

ATLAS and the protection of personal data

ATLAS is designed to make your obligations easier under Türkiye's Personal Data Protection Law No. 6698 (KVKK) — and, by the same architecture, under the EU General Data Protection Regulation (GDPR).

You are the data controller

ATLAS runs on your company's own hardware. The personal data it processes — employee records, attendance and leave records, customer contact details — stays within your company's boundaries. It is not transferred to the team that builds ATLAS and it is not stored on third-party servers.

Cross-border transfers

Keeping data inside the company removes one of the hardest problems in both KVKK and GDPR — cross-border data transfer — before it arises. Even if you choose the cloud-based AI option, no raw personal data is sent; only de-identified summary figures are passed on. If you want no personal data sent at all, you use the local model option — in which case data never leaves the machine.

Data minimisation

ATLAS processes only the data the relevant department needs. It does not collect unnecessary data and does not read fields it has no use for.

Access limitation

Role-based authorisation is the technical implementation of the “access for authorised persons only” principle that both regimes require. The authorisation matrix is defined together with you during implementation.

Records of processing

Which data was entered and viewed, by whom and when, is recorded. That log can be used to support your audit and accountability obligations.

Erasure and retention

Because the data sits in your own system, you apply retention periods and erasure requests according to your own policy. There is no external provider to request deletion from and no process to wait on.

Please note: this text is for information only and does not constitute legal advice. Your company's compliance documentation (privacy notices, consent forms, records of processing, registry filings) should be prepared by your own legal counsel.

Let us go through your security questions with your technical team.

Invite your IT lead to the demo call.

Request a live demo