TokenAtlas
Security & Privacy at TokenAtlas

Security you can inspect, not just marketing you have to trust.

TokenAtlas is AI financial infrastructure — teams route real budget decisions through it. This page documents exactly how we protect that trust: what we encrypt, what we isolate, what we never collect, and how we respond when something goes wrong.

Hardened Authentication

Email + OAuth via a managed identity provider with rotating refresh tokens, email verification and session revocation.

Encryption Everywhere

TLS 1.2+ in transit with HSTS. AES-256 at rest for databases, storage and backups.

No Prompt Logging

We never ingest, log or store your raw LLM prompts or completions — TokenAtlas only sees pricing and token metadata.

Tenant Isolation

Row-level security policies on every customer table, enforced at the database — not just the app layer.

Platform Security

TokenAtlas is a modern SaaS built on a hardened, edge-served stack. We follow defense-in-depth: multiple independent controls at the network, application and data layers so that a single failure does not expose customer data.

  • Least-privilege access for all production systems
  • Continuous dependency and secret scanning in CI
  • Immutable audit trail for privileged operations
  • Automated security review on every deploy

Infrastructure

The application runs on globally distributed edge infrastructure. Databases and object storage are provisioned in hardened, SOC 2-aligned regions operated by our cloud providers (Cloudflare and Supabase/AWS). Environments are strictly separated: production data never flows into staging or development.

  • Isolated production, staging and preview environments
  • Infrastructure-as-code with peer-reviewed changes
  • Provider-managed patching for the underlying OS and runtime
  • DDoS protection and WAF at the edge

Encryption at Rest

All customer records — including account profiles, saved calculations, workspaces and audit logs — are encrypted at rest using AES-256. Encryption keys are managed by our infrastructure provider's KMS, rotated on a regular schedule, and are never exposed to application code. Automated backups inherit the same encryption and are stored in a separate access domain from production.

Encryption in Transit

Every request between your browser, our API and internal services is served over TLS 1.2+ using modern cipher suites. HSTS is enforced site-wide, mixed content is blocked, and we redirect all plain-HTTP traffic to HTTPS. Internal service-to-service traffic is authenticated and encrypted.

Authentication

Sign-in is handled by a managed identity provider with battle-tested primitives. Sessions use short-lived access tokens plus rotating refresh tokens, email addresses are verified before privileged actions, and OAuth is available for password-less access via major providers.

  • Rotating refresh tokens with server-side revocation
  • Email verification on every new account
  • OAuth via Google (and additional providers on request)
  • Ready for TOTP-based multi-factor authentication

Authorization

Application-level roles (owner, admin, member) gate what a user can do inside a workspace. At the data layer, every user-facing table enforces row-level security policies bound to the authenticated user or workspace — meaning even a bug in application code cannot return another tenant's rows. Privileged server functions additionally require an explicit role check before elevated operations run.

AI Data Privacy

TokenAtlas is a cost intelligence platform, not an LLM proxy. We operate on pricing metadata, token counts and calculator inputs — we never ingest, log or persist raw prompts or model completions. When you connect a provider API key, it is stored encrypted, used only to fetch usage/billing metadata, and never shared with any third party.

  • No prompt or completion logging, ever
  • Provider API keys encrypted at rest, scoped to your workspace
  • AI features (insights, summaries) run on aggregated metadata only
  • You can revoke provider access from Settings at any time

User Data Protection

We collect only what is necessary to operate the product: account identifiers, workspace membership, saved calculations, usage metadata and standard request logs. We do not sell user data, do not use it to train third-party AI models, and do not enrich it with data brokers.

Data Retention

Operational data is retained only as long as it is needed to deliver the service. Application logs are retained for 30 days. Backups are retained for 30 days on a rolling window and then permanently deleted. When you delete your account, associated personal data is removed from primary systems within 30 days and expires from backups within the backup retention window.

GDPR Compliance

TokenAtlas is built to be GDPR-aligned. We have a lawful basis for every processing activity, practise data minimisation, and honour data-subject rights (access, rectification, erasure, portability, objection) within 30 days of a verified request.

  • EU data processing available where supported by our providers
  • Data Processing Addendum (DPA) available on request
  • Documented subprocessor list, updated on change
  • Privacy contact: privacy@tokenatlas.co

Security Best Practices

We give customers the primitives to run TokenAtlas safely inside their organisation and recommend the following operational hygiene.

  • Use a unique, high-entropy password or an OAuth provider
  • Enable multi-factor authentication once available in your workspace
  • Rotate provider API keys on a regular cadence
  • Grant workspace access using the least privilege that gets the job done
  • Review the audit log for unexpected actions

Responsible AI Usage

The AI features inside TokenAtlas — spend insights, model recommendations, cost narratives — operate on aggregated, non-sensitive metadata. Outputs are advisory and always clearly labeled as AI-generated. We do not use customer data to fine-tune or evaluate third-party models, and we do not use AI to make automated decisions that would produce legal or similarly significant effects on end users.

Secure Integrations

Third-party integrations (Stripe/Paddle for billing, Supabase for data, Cloudflare for the edge) are scoped to the minimum permissions needed. Webhooks verify signatures using HMAC and constant-time comparison before any state change. Outbound calls to LLM provider billing APIs are read-only.

API Security

Every authenticated endpoint validates its input with a schema, verifies the caller's session on every request, and enforces the same row-level security policies as the UI. Rate limiting protects against abuse. Public endpoints (webhooks, health checks) verify signatures or use narrow read-only policies — never blanket access.

Incident Response

We monitor production continuously for anomalies. If an incident affects customer data, we notify affected customers without undue delay and, where required, within 72 hours of becoming aware, in line with GDPR Article 33. Post-incident, we publish a root-cause summary and the corrective actions taken.

Future Compliance Roadmap

TokenAtlas does not yet hold formal third-party certifications, and we won't claim ones we don't have. Our roadmap prioritises the controls customers ask for most.

  • SOC 2 Type I readiness assessment
  • Formal subprocessor page with change notifications
  • Customer-managed audit log export
  • Region pinning for enterprise workspaces
Report a vulnerability

Found something? Email security@tokenatlas.co. We acknowledge reports within 2 business days and coordinate disclosure with the reporter.

Privacy & DPA requests

Data subject requests and DPA signatures: privacy@tokenatlas.co. See our Privacy Policy for the full processing details.

A note on compliance: TokenAtlas is built on security and privacy best practices, and we're pursuing formal attestations on the roadmap above — but we don't currently hold SOC 2, ISO 27001 or similar third-party certifications, and we won't claim ones we don't have. If your procurement team needs a security review, please contact us and we'll respond with the artefacts we do have.

Ready to take control of your AI costs — securely?

Get Started Free