Your data

Your data, and the proof it stays yours.

Procurement is a record people rely on later — an auditor, a regulator, a supplier in dispute. So Atlas is built on one idea: your records cannot be quietly deleted or altered, not even by your own administrators, and no action by anyone, ourselves included, escapes a log that cannot be edited. Enforced by the software, not promised in a policy.

CanadaBorn and built in Canada; hosted in Toronto today — the platform is architected to deploy in any region a client needs
Sealed & anchoredA hash-chained log the system can't edit, anchored off-site hourly
Two-admin ruleNo single admin can remove another
Verified backupsHourly, off-site as ciphertext, immutable, proven to restore

Download the controls & evidence sheet (PDF)

Integrity

Nothing important can be destroyed.

The records and evidence a decision rests on cannot be deleted from inside the product — only ever changed in status, always with a trace.

Records, not deletions

Requisitions, orders, invoices, contracts and bids are never removed — they move through states. Suppliers are suspended; people deactivated, their past actions still resolving to their name.

Enforced in code

Evidence stays put

Once a requisition is approved, its documents are locked in place. A supplier's submitted bid documents are kept as part of the competition record — not something an admin can quietly remove.

Enforced in code

Even settings are recoverable

Removing configuration — an approval rule, a delegation — records the full removed item into the sealed log first, so it is attributable and can be restored.

Enforced in code
The record of who did what

The activity log cannot be edited — and tampering shows.

Every significant action is written to an append-only log the system cannot change or delete. Each entry is sealed to the one before it, and the log's position is anchored off-site every hour into storage that cannot be rewritten — so editing one line, or replacing the whole log, is caught.

Change entry 1,204 after the fact and its seal no longer matches — and because every later entry was sealed using the one before it, they all break too. The database refuses edits and deletions outright, and the hourly off-site anchor makes even a wholesale rewrite detectable. We verify the chain and its anchor on every backup restore.

Access

Only the right people, and never one alone.

Roles decide what each person can see and do, and the most dangerous action of all — removing an administrator — takes two people.

Roles & least privilege

A requester can't approve their own spend; only finance releases a payment. Access can be cut off the moment someone leaves.

In production

Two-factor, enforceable

TOTP two-factor can be required for everyone or for admins, and passwords must meet a real strength policy.

In production

The two-admin rule

Removing, deactivating or demoting an administrator needs a different admin to approve it first — so one rogue or stolen account can't lock everyone out. The last admin can never be removed.

Enforced in code
Residency & encryption

Born in Canada. Hosted where you need it.

Backbone Atlas was designed and built in Canada, and every workspace today runs from our Toronto region. The platform is not tied to one country: when a client signs, we stand up a dedicated cloud instance in the region their data-residency rules require.

Canadian by default

Hosted in Toronto today. Traffic passes through Cloudflare's worldwide network and encrypted backups are held by Backblaze; a dedicated instance in your own region is available when you sign.

In production

A database of your own

Every company gets its own separate database — one customer physically cannot read another's. Isolation comes from that separation by design, verified by our own adversarial testing.

In production

Encrypted, keys apart

Full-volume encryption at rest, plus field-level encryption for bank details and secrets — keys held outside the database. TLS + HSTS in transit.

In production
Continuity

Backed up, off-site, and proven to restore.

A backup nobody has restored is a hope, not a backup — so we prove ours, and we lock them where ransomware cannot reach.

Hourly & verified

Every hour, and each copy is opened and checked for soundness as it's taken.

In production

Off-site, immutable, unreadable

A copy goes to a second, independent provider — encrypted before it leaves and locked so it cannot be altered or deleted, even with a stolen key.

In production

Continuous, not just hourly

Every company’s database is replicated as it is written, second by second, to encrypted storage — so a mistake inside the system costs about a second, and losing the whole server about five minutes.

In production

Restore is proven

We regularly pull a backup back, open it, and verify the audit chain — and we restore a single company’s data without touching anyone else’s.

In production
Ownership

Your data is yours.

What you put into Atlas remains your record, under your control — to keep intact, to keep private, and to take with you.

It stays intact

Records and evidence can't be destroyed or rewritten from inside the product — the protections here are enforced, not promised.

It stays private

Isolated per company, encrypted at rest and in transit, and pushed off-site only as ciphertext a third party can't read.

It stays portable

An administrator can export the whole workspace to open CSV files at any time, from inside the product. Returning or deleting your data is a clean, complete operation.

Straight with you

What Atlas does not do — said plainly.

Trust is easier to give when the edges are named rather than hidden.

Limit
What's true today
No SOC 2 / ISO 27001
We don't hold a formal certification. We're built for mid-market organisations where the controls on this page matter more than a certificate; if your policy requires SOC 2 or ISO 27001, we're not the right fit yet.
Support access is logged, not zero
To support you, our operators can reach your workspace. That access is restricted and, like everything else, recorded in the same sealed log. Your data is never sold, shared, or used to train anyone's models.
Fast recovery, not zero-downtime
One Canadian region with fast, tested recovery, not hot-standby failover. Honest availability target: 99.5%. Recovery point about one second on the server, about five minutes off-site.
A newer product, and we say so
No borrowed logos, no invented numbers. What's real today is a system whose data protections are testable now — which is what actually protects your records.
Due diligence

For your IT & security team.

The questions a security review actually asks, answered straight — including where the honest answer is a limit. The downloadable evidence sheet maps each to how you can verify it.

If ransomware hit your server, would it reach our backups?
No. Off-site backups use immutable, versioned storage (Backblaze Object Lock): once written, a copy cannot be altered or deleted — not by malware on the server, not with a stolen backup key. A second copy sits on a founder-controlled drive kept off the cloud entirely, which server-side ransomware physically cannot reach. Your backup history survives even a full compromise of the server.
Could a backup taken after infection overwrite the good ones?
No. Backups are versioned and immutable, and older snapshots are retained (hourly recent history, then daily). An encrypted post-infection snapshot sits alongside the clean earlier ones — never replacing them — so recovery is to a point before the infection. Nightly file-integrity monitoring shortens the window an infection could go unnoticed.
Are the backups readable if the backup account is breached?
No. Every backup is client-side encrypted before it leaves the server — the provider stores only ciphertext with scrambled filenames and holds no key. A breach there exposes nothing usable.
How fast could we be running again after an attack?
Rebuild onto a fresh server and restore from the immutable off-site copy: roughly 30–60 minutes. If only the server is lost and the encrypted data volume survives, closer to 15–30 minutes. The procedure is written down and rehearsed.
Ask us the awkward question

Bring your IT team's hardest question to the demo.

Ransomware, breach, retention, sub-processors — ask it directly, and we'll show you the mechanism, not a slide.

Book a demo