Procurement is a record people rely on later — an auditor, a regulator, a supplier in dispute. So Atlas is built on one idea: your records cannot be quietly deleted or altered, not even by your own administrators, and no action by anyone, ourselves included, escapes a log that cannot be edited. Enforced by the software, not promised in a policy.
The records and evidence a decision rests on cannot be deleted from inside the product — only ever changed in status, always with a trace.
Requisitions, orders, invoices, contracts and bids are never removed — they move through states. Suppliers are suspended; people deactivated, their past actions still resolving to their name.
Enforced in codeOnce a requisition is approved, its documents are locked in place. A supplier's submitted bid documents are kept as part of the competition record — not something an admin can quietly remove.
Enforced in codeRemoving configuration — an approval rule, a delegation — records the full removed item into the sealed log first, so it is attributable and can be restored.
Enforced in codeEvery significant action is written to an append-only log the system cannot change or delete. Each entry is sealed to the one before it, and the log's position is anchored off-site every hour into storage that cannot be rewritten — so editing one line, or replacing the whole log, is caught.
Change entry 1,204 after the fact and its seal no longer matches — and because every later entry was sealed using the one before it, they all break too. The database refuses edits and deletions outright, and the hourly off-site anchor makes even a wholesale rewrite detectable. We verify the chain and its anchor on every backup restore.
Roles decide what each person can see and do, and the most dangerous action of all — removing an administrator — takes two people.
A requester can't approve their own spend; only finance releases a payment. Access can be cut off the moment someone leaves.
In productionTOTP two-factor can be required for everyone or for admins, and passwords must meet a real strength policy.
In productionRemoving, deactivating or demoting an administrator needs a different admin to approve it first — so one rogue or stolen account can't lock everyone out. The last admin can never be removed.
Enforced in codeBackbone Atlas was designed and built in Canada, and every workspace today runs from our Toronto region. The platform is not tied to one country: when a client signs, we stand up a dedicated cloud instance in the region their data-residency rules require.
Hosted in Toronto today. Traffic passes through Cloudflare's worldwide network and encrypted backups are held by Backblaze; a dedicated instance in your own region is available when you sign.
In productionEvery company gets its own separate database — one customer physically cannot read another's. Isolation comes from that separation by design, verified by our own adversarial testing.
In productionFull-volume encryption at rest, plus field-level encryption for bank details and secrets — keys held outside the database. TLS + HSTS in transit.
In productionA backup nobody has restored is a hope, not a backup — so we prove ours, and we lock them where ransomware cannot reach.
Every hour, and each copy is opened and checked for soundness as it's taken.
In productionA copy goes to a second, independent provider — encrypted before it leaves and locked so it cannot be altered or deleted, even with a stolen key.
In productionEvery company’s database is replicated as it is written, second by second, to encrypted storage — so a mistake inside the system costs about a second, and losing the whole server about five minutes.
In productionWe regularly pull a backup back, open it, and verify the audit chain — and we restore a single company’s data without touching anyone else’s.
In productionWhat you put into Atlas remains your record, under your control — to keep intact, to keep private, and to take with you.
Records and evidence can't be destroyed or rewritten from inside the product — the protections here are enforced, not promised.
Isolated per company, encrypted at rest and in transit, and pushed off-site only as ciphertext a third party can't read.
An administrator can export the whole workspace to open CSV files at any time, from inside the product. Returning or deleting your data is a clean, complete operation.
Trust is easier to give when the edges are named rather than hidden.
The questions a security review actually asks, answered straight — including where the honest answer is a limit. The downloadable evidence sheet maps each to how you can verify it.
Ransomware, breach, retention, sub-processors — ask it directly, and we'll show you the mechanism, not a slide.
Book a demo