Compliance Policy
Technology stewardship means protecting customer information through secure design, transparent practices, and respect for customer ownership.
Technology Built with Stewardship
Technology should respect the people who use it.
SoAtomic is committed to protecting customer information through secure design, least-privilege administration, and transparent operational practices. We believe organizations should own their technology, understand how their information is handled, and remain in control of their data.
Whenever practical, we recommend technologies that minimize unnecessary data collection, reduce administrative exposure, and support modern security practices.
Whenever practical, SoAtomic recommends customer-owned accounts and infrastructure. Domains, cloud platforms, identity providers, productivity suites, websites, and business systems should remain under the customer's ownership, ensuring long-term independence and avoiding unnecessary vendor lock-in.
Customer Data
Our principles are straightforward:
- Customers own their data.
- We access only the information necessary to perform requested work.
- We never sell customer information.
- We never monetize customer data.
- We minimize retained information.
- Administrative access is documented and can be revoked.
When an engagement ends, ownership remains entirely with the customer and our administrative access is removed.
Security Philosophy
Security is not a product.
It is the result of good decisions made consistently.
Whenever appropriate, SoAtomic recommends:
- Multi-factor authentication
- Passkeys
- Device encryption
- Least-privilege administration
- Regular patching
- Security monitoring
- Zero Trust architecture
- End-to-end encryption where supported
No system is perfectly secure, but thoughtful design significantly reduces risk.
Zero Trust
Modern systems should assume that no user, device, or network is trusted by default.
Where appropriate, SoAtomic designs environments that:
- Verify identity continuously
- Grant only the minimum required access
- Limit lateral movement
- Support rapid access revocation
- Reduce the impact of compromised credentials
Encryption
Whenever supported by the selected platforms, SoAtomic recommends encryption:
- In Transit
- At Rest
- End-to-End Encryption (E2EE)
End-to-end encryption ensures that only the intended participants can access protected information—not even the service provider.
Availability depends on the capabilities of the selected products.
CCPA
For organizations subject to the California Consumer Privacy Act (CCPA), SoAtomic follows operational practices that support responsible handling of personal information.
Our business practices include:
- No sale of customer information
- Minimal data collection
- Transparent administrative access
- Secure handling of customer information
We help customers implement technology that supports their compliance obligations, but we do not provide legal advice or certify regulatory compliance.
GDPR
For organizations operating under the General Data Protection Regulation (GDPR), SoAtomic supports privacy-by-design through technologies such as:
- Identity management
- Access controls
- Audit logging
- Encryption
- Data minimization
- Retention planning
We provide technical implementation and operational guidance. Legal compliance remains the responsibility of the customer organization.
Supported Compliance Frameworks
Many organizations operate under regulatory or contractual requirements beyond GDPR and CCPA.
While SoAtomic does not provide legal or compliance certification services, we help implement technology that supports widely adopted security and governance frameworks.
Depending on the organization's needs, we can help build environments that align with practices commonly associated with:
- SOC 2
- HIPAA
- FERPA
- PCI DSS
- NIST Cybersecurity Framework (CSF)
- CIS Controls
Support may include:
- Identity and access management
- Multi-factor authentication
- Passkeys
- Endpoint security
- Encryption at rest and in transit
- Audit logging
- Device management
- Least-privilege administration
- Backup and recovery planning
- Security monitoring
- Documentation of administrative access
Technology is only one component of compliance. Policies, employee training, legal obligations, and organizational governance remain the responsibility of the customer.
Third-Party Services
Many customer environments rely on cloud platforms, identity providers, payment processors, communication services, and other third-party providers.
Each provider maintains its own security practices, compliance programs, and privacy policies.
When recommending vendors, SoAtomic evaluates:
- Security
- Reliability
- Transparency
- Customer ownership
- Vendor independence
We recommend technology based on long-term stewardship rather than vendor lock-in.
Transparency
Customers should always know:
- What systems are being used
- Who has administrative access
- Why access is required
- How information is protected
- How our administrative access can be removed
Stewardship means leaving customers with more ownership and understanding than they had before working with us.
Note:
This page describes SoAtomic's operational philosophy and technical practices.
It is provided for informational purposes only and should not be interpreted as legal advice or as a certification of compliance with any law, regulation, or security framework.
