Creately Atlas is designed for HR and people operations teams that need an always-current view of employee and organizational data. Atlas is built on Creately’s platform security framework, which includes AES-256 encryption for document content at rest, TLS 1.2 or higher for data in transit, role-based access controls, least-privilege access practices, regional hosting options, and formal privacy processes. If you are evaluating Atlas for sensitive organizational data, these are the controls to review first.
Atlas Security and Data Trust at a Glance
| Area | What Creately publishes |
|---|---|
| Encryption at rest | AES-256 encryption for document content and customer data at rest |
| Encryption in transit | TLS 1.2 or higher over public networks |
| Access controls | Role-based access control, least-privilege access, MFA options, and SSO support |
| Regional hosting | United States, European Union, and Australia |
| Backups | Datastores backed up every 24 hours with redundancy designed for high availability |
| Retention | Data is kept only as long as necessary for service delivery, legal obligations, disputes, and agreements |
| Evidence | Security package under NDA, including SOC 2 Type 2 and ISO 27001 materials |
How Creately Atlas Protects Employee and Org Data
Atlas is designed for CHROs, People Ops teams, and HR leaders who need to work with live organizational data without replacing their HRIS. That makes trust a buying requirement, not a nice-to-have. Our security controls address the questions buyers commonly ask first: how data is encrypted, who can access it, where it is stored, how long it is retained, and what compliance evidence is available during review.
When evaluating Atlas, review these platform-wide security controls and confirm the deployment, region, and contractual requirements that apply to your organization during procurement.
Encryption, Access, and Sharing Controls
We encrypt customer data in transit using TLS 1.2 or higher. Document content is encrypted at rest using AES-256, while other customer data, including backups and metadata, is protected using FIPS-validated encryption mechanisms. Administrative and customer-data access is governed by role-based access controls and the principle of least privilege.
For employee and organizational data, these controls matter in day-to-day use:
- Limit shared organizational views to the appropriate audience.
- Review access to sensitive fields before making them more widely available.
- Include identity controls such as SSO and MFA in the rollout checklist for any production workspace containing employee information.
Access to customer data is logged and audited internally. Our support teams access customer information only when necessary to resolve an open request and with the customer’s explicit request or consent.
Data Residency, Transfers, and Retention
Customer information is stored and processed in the region selected during signup, with regional hosting options in the United States, European Union, and Australia. If your HR or legal team has a data residency requirement, confirm the target region before rollout rather than after migration work begins.
We retain personal data and user content only as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Usage data is generally retained for a shorter period unless it is needed for security, product improvement, or legal reasons. Users can also request deletion through our support team, giving procurement teams a clear retention and deletion process to review.
Our datastores are backed up every 24 hours, and our systems use redundancy and clustering. These measures do not replace your organization’s recovery review, but they provide a baseline for assessing operational resilience.
Compliance, Reviews, and Security Evidence
Creately has completed a SOC 2 Type 2 audit, is ISO 27001 certified, and supports HIPAA compliance for healthcare and life sciences organizations. We are also prepared to sign Business Associate Agreements (BAAs) with enterprise partners. Enterprise customers can request our security package under NDA, including the latest SOC 2 Type 2 report and ISO 27001 certificate.
These safeguards and materials do not replace your organization’s own security and compliance review. They provide a clear starting point when evaluating Atlas for employee and organizational data:
- Verify the region required by your organization.
- Confirm your SSO, MFA, and access-model requirements.
- Review the retention and deletion workflows.
- Request the latest security package during procurement.
- Validate industry-specific requirements against the current agreement and deployment plan.
What HR Teams Should Check Before Approving Atlas
- Confirm which employee and org fields will be stored, synced, or exposed to managers.
- Define who needs edit access, review access, and executive read access before rollout.
- Decide the residency region up front if legal or works-council review requires it.
- Ask for the current security package if procurement needs formal evidence beyond the website.
- Review support, audit, and deletion workflows with the stakeholders who own HR data governance.
- Keep the evaluation grounded in the exact use case: org visibility, scenario planning, or leadership reporting can require different access boundaries.

