Trust
Security at Atrium
Atrium is designed to keep each studio’s projects, clients, approvals, and financial records private and auditable.Effective 28 July 2026 · Last updated 28 July 2026Tenant and role isolation
Production records carry studio ownership and are protected by membership-scoped database policies. Application roles limit project, approval, procurement, finance, reporting, and administration capabilities. Private client access does not create studio membership.
Data and credential protection
Traffic is encrypted in transit. Project files use private storage and scoped access. Service-role credentials and provider secrets stay in managed server environments and are never exposed to browser code. Sensitive provider events require signature verification and idempotent processing.
Auditability and resilience
Important identity, approval, commercial, payment, procurement, and administrative mutations create auditable evidence. Forward-only migrations, automated verification, health checks, and deployment rollback procedures protect release integrity. Database and file recovery depend on the backup controls configured for the studio’s production service.
Responsible disclosure
Please report a suspected vulnerability privately through the security contact in your Atrium agreement. Include affected surface, reproducible steps, impact, and supporting evidence. Do not access another party’s data, degrade service, or publish an unresolved issue. We will acknowledge and prioritize valid reports.