TRUST & SECURITY
Liles Automation · Atlas
LILES AUTOMATION
Trust & Security
POSTURE LIVE
← back to hub
// Trust & Security

Your business data, safely automated.

Atlas handles your leads, customers, documents, and conversations. Here's exactly how we protect that data, who can see it, and what rights you have over it.

Plain English · No legalese · Updated regularly
Ask a security question
🔒
Encrypted everywhere
TLS 1.3 in transit · AES-256 at rest
🏢
Owner-only access
No team data sharing · no analytics resale
🌍
SOC 2-compliant hosts
Every sub-processor independently audited
⏱️
24-hour incident SLA
Written notification commitment
🔑// CONNECTION · NO PASSWORDS, EVERoauth only

Atlas plugs into your phone, inbox, calendar, spreadsheets, and CRM without ever asking for a password.

  • You authorize, we never see credentials. You click "Connect" and sign in on your provider's own page (Google, your CRM). Your password goes to them — never to us.
  • We hold a revocable token, not your login. What Atlas receives is a scoped access token that only permits the specific actions you approved.
  • Encrypted at rest. Tokens are stored encrypted (AES-256) on SOC 2 Type II certified infrastructure.
  • You hold the kill switch. Revoke Atlas's access anytime from your own Google/CRM security settings — instantly, without asking us.
  • We can't leak what we never hold. No password database exists here to be breached.
📥// WHAT WE COLLECTneed-to-run only

Only what's necessary to run the automations you bought. Nothing else.

Lead & customer info — name, phone, email, address, project details from inbound forms or your CRM
Conversation history — Slack DMs with Atlas, SMS threads with customers, email replies
Business operating data — your jobs, quotes, invoices, calendars, team rep list
Documents you send Atlas — Xactimate estimates, invoices, permits, contracts
Audit logs — every action Atlas takes, for your review
Voice/tone samples (optional) — 5-10 of your past emails, used only to tune Atlas's writing to sound like you
🚫// WHAT WE DON'T COLLECTso you never wonder

Things we explicitly never touch, so you don't have to wonder.

Payment card numbers — we never see or store them. Billing is handled by Stripe.
Behavioral tracking pixels — no Facebook Pixel, no Google Analytics tracking on customer data
Personal data unrelated to business — we don't scrape social media, browsing history, etc.
Data we'd sell or share — your customer list is your asset, period. We don't market to it, share it, or analyze it for our own purposes.
Training data for AI — your conversations and customers are NEVER used to train AI models. Our AI vendors (Anthropic, and Groq for fast-path inference) do not train on API data — Anthropic is contractually prohibited from it.
Surveillance of your team — we don't track keystrokes, screen time, productivity metrics, or any individual behavior
🌐// WHERE YOUR DATA LIVESby tier

Physical infrastructure, by tier. Your data & connected accounts stay isolated — never co-mingled. You can ask which region you're hosted in at any time.

Compute

Railway (US) or Hetzner Cloud (EU)
Both SOC 2 Type II + ISO 27001 certified. Enterprise clients choose the region.

Database

PostgreSQL · daily encrypted backups
Pro tier: logically isolated schema — your records never co-mingled with another client's. Enterprise tier: dedicated database instance.

AI inference

Anthropic Claude API (US-region)
SOC 2 Type II certified · API data not retained beyond response · never used for training.

Phone & SMS

Twilio (A2P 10DLC registration at onboarding)
SOC 2 Type II · HIPAA-eligible · your business is registered with US carriers as part of setup.
🔒// ENCRYPTIONno exceptions

Industry-standard everywhere, no exceptions.

LayerStandardNotes
Data in transitTLS 1.3All API traffic · web traffic · webhooks
Data at restAES-256Database · backups · object storage
Your connection credentialsApplication-layer encryption (Fernet/AES)Slack, Google & CRM tokens are encrypted inside the database — the decryption key lives only in the runtime environment, so a copy of the database alone can't read them
Application logsPII-scrubbedCustomer message content is never written to logs · phone numbers & emails are masked · full detail lives only in your client-scoped, retention-swept audit log
Database backupsAES-256 + encrypted-at-rest snapshotsStored in separate region from primary
API keys & secretsEncrypted in secrets managerRotated quarterly · never in plain-text logs
Session tokensHMAC-signed · short-livedSlack/Twilio webhook signature verification on every request
📱// TCPA · OPT-OUT SAFETYimpossible to bypass

Every text Atlas sends is opt-out-safe. STOP is honored automatically, at the lowest level of every send path — so no skill can ever bypass it.

  • STOP auto-handles instantly. If a customer replies STOP, UNSUBSCRIBE, CANCEL, END, or QUIT, they're added to a permanent blocklist and Atlas never texts them again.
  • The check lives below every skill. Speed to Lead, the Receptionist, Follow-Up, Reactivation — every path that sends a message passes through one blocklist gate. There is no code path that can skip it.
  • A2P 10DLC registration handled for you. During onboarding we file your business's carrier registration through Twilio — the legally compliant route for business SMS (carrier approval typically takes 1–2 weeks).
  • Quiet hours respected. Automated texts honor reasonable local sending windows — no 2 AM messages to your customers.
  • Blocked attempts are logged. Every time the blocklist stops a send, it's recorded in your audit log for proof of compliance.
🚦// YOUR FIRST MONTH · TRAINING WHEELSnothing sends without your okay

Atlas doesn't talk to your customers unsupervised on day one. It earns that.

  • Every draft comes to you first. For the first ~30 days, every customer-facing text and email Atlas writes is held for your one-tap approval in Slack before it sends. This is enforced in the engine across every skill — not a setting you have to remember to turn on.
  • Your edits tune the voice — and Atlas keeps learning it. Atlas is seeded with samples of how you actually write, and every week it automatically refreshes its voice from your real replies and sent emails. The longer it runs, the more it sounds like you — it never learns from its own output, only from yours.
  • You decide when the wheels come off. When you're approving without editing, supervision ends — and can be extended or re-enabled any time you want it back.
💰// PRICE VALIDATIONno fabricated numbers

Atlas never invents a price. Any number that goes out to a customer is checked against your real catalog before it leaves the building.

  • Catalog-anchored. Quotes and prices are validated against your approved price list, within a tight tolerance (5%). Anything outside that is intercepted.
  • Channel-aware intercept. If a figure can't be verified, Atlas does not send it to the customer — it pauses and routes the message to you instead.
  • You get an urgent alert. A flagged price fires an immediate Slack alert so you can confirm or correct before anything reaches the customer.
  • Protects your margin and your word. No surprise discounts, no hallucinated totals, no quote you'd have to walk back.
📝// AUDIT LOGGINGappend-only

Every action Atlas takes is written to an append-only audit log. Nothing is silently edited or erased.

  • Append-only by design. Records are added, never overwritten or deleted out from under you — so the trail can't be quietly rewritten.
  • Every action, timestamped. Each text sent, doc processed, lead booked, price flagged, and STOP honored lands in the log with a timestamp.
  • Yours to inspect on demand. Full read access to the log of everything Atlas has done on your behalf, any time you ask.
  • Retained for compliance. Audit logs are kept for 12 months by default, then archived — available on request for compliance reviews.
🔑// WHO CAN ACCESS YOUR DATAshort, accountable list

A short, accountable list.

  • Eric Liles (owner of Liles Automation) — direct access for support, debugging, and tuning
  • Automated systems — Atlas itself, scheduled jobs, monitoring tools (no human reads the data they process)
  • You — full read access to all your data via your Slack workspace and Google Sheets

Access controls in place:

  • Two-factor authentication required on every internal tool
  • Database access logged · audit trail retained for 12 months
  • No shared credentials · all access tied to identifiable accounts
  • Subcontractors (when used) sign NDAs and DPAs before being granted access
🤝// SUB-PROCESSORSwritten notice before changes

Every third-party service we use, what data they touch, and their certifications. We notify you in writing before adding new ones.

ServicePurposeData sharedCompliance
Anthropic
claude.ai
AI text generation (Atlas's brain) Conversation contents at inference time only SOC 2 Type II
Twilio
twilio.com
SMS & voice for Receptionist + Speed to Lead Phone numbers · SMS bodies SOC 2 + HIPAA
Groq
groq.com
Fast AI inference (router fast-path for simple text) Conversation contents at inference time only · not used for training SOC 2 Type II
Google Workspace
google.com
Sheets · Gmail · Calendar (under your OAuth) Whatever you grant via OAuth scopes SOC 2 + ISO 27001
Railway
railway.app
Compute hosting (Core & Pro tiers) App code + database SOC 2 Type II
Hetzner Cloud
hetzner.com
Dedicated compute (Enterprise tier) App code + database (isolated VPS) ISO 27001
Stripe
stripe.com
Billing & payments Your billing details · we never see card numbers PCI DSS Level 1
Vercel
vercel.com
Demo hub + public marketing site only No customer data · static files only SOC 2 Type II
Slack
slack.com
Atlas's chat interface (your workspace) Messages you send Atlas SOC 2 + ISO 27001 + FedRAMP
// COMPLIANCE POSTUREtoday & next

Where we stand today and what's coming.

StandardStatusNotes
SOC 2 Type IIOn roadmapPlanned as we scale · every infrastructure sub-processor we run on (Railway, Anthropic, Twilio, Stripe, Slack) is independently SOC 2 audited today.
GDPR-readyYesEU clients hosted in Hetzner (Germany) · DPA available on request
CCPA-compliantYesCalifornia Consumer Privacy Act · right-to-delete honored within 30 days
TCPA · A2P 10DLCRegistered at onboardingWe file your carrier registration during setup (approval typically 1–2 weeks) · STOP auto-honored on every send path
HIPAAEnterprise tier onlyCustom BAA available · only when explicitly contracted
Annual penetration testPlanned 2027Will be commissioned once we reach 10+ Enterprise clients
📅// DATA RETENTIONconfigurable per client

How long we keep your data, and what happens when you leave. Retention is configurable per client — tell us your policy and we'll set it.

Custom retention is real

The defaults below are exactly that — defaults. We can shorten or lengthen retention windows to match your internal policy or your insurer's requirements. Just say the word and we configure it for your account.

While active

Indefinitely, in your live database
You can export everything to CSV at any time

After you cancel

30-day grace period · then permanently deleted
Backups purged within 90 days. Written confirmation provided.

Backups

90 days encrypted · stored in separate region
For recovery only · never accessed for analytics

Audit logs

12 months retained, then archived
Available on request for compliance reviews
⚖️// YOUR RIGHTSno lock-in

It's your business. It's your data. No locked-in clauses.

  • Export anytime. Full CSV/JSON dump of all your data within 7 business days of a request, no charge.
  • Delete anytime. 30-day grace period after cancellation, then permanent deletion with written confirmation.
  • Inspect anytime. Full audit log of every action Atlas has taken on your behalf, available on demand.
  • Restrict processing. You can pause specific skills, retroactively delete specific conversations, or limit what Atlas can do.
  • No long-term lock-in. Cancel any time with 30 days notice. No multi-year contracts (unless you opt in for the Enterprise annual discount).
  • Portability. All exported data is in standard open formats — Google Sheets, CSV, JSON. You can move it to another system on day one.
🚨// INCIDENT RESPONSEwhat & how fast

What we'll do — and how fast — if something goes wrong.

Event typeNotification SLAReport SLA
Data breach affecting your recordsWithin 24 hours of discoveryDetailed post-mortem within 7 days
Service outage > 30 minutesWithin 1 hourPublic status page update + email recap
Unauthorized access attempt (blocked)Monthly summaryIncluded in standard audit log
Sub-processor incident (e.g. Anthropic outage)Within 2 hours of confirmationStatus update as situation evolves
// ENTERPRISE-TIER GUARANTEESfrom $6,500/mo

Additional commitments included when you're on the Atlas Enterprise plan. The dedicated-infrastructure guarantees below apply to Enterprise only.

Enterprise tier · from $6,500/mo + $10,000 setup

Comes with dedicated infrastructure and signed contractual guarantees beyond what's listed above. These dedicated-server / own-VPS / own-Postgres commitments are scoped to the Enterprise tier.

  • Custom Data Processing Agreement (DPA) — negotiated and signed at onboarding
  • Dedicated server — your own VPS, physically separated from all other clients (Enterprise only)
  • Dedicated database — your own Postgres instance, not a shared schema (Enterprise only)
  • Custom retention — tell us your policy, we follow it
  • Custom incident SLA — typically tighter than the standard 24-hour notification
  • HIPAA-eligible — signed BAA available for medical/dental clients
  • Annual security review — written attestation of controls in place
  • Right of audit — on reasonable notice, you can audit our practices
📬// CONTACT~1 business day

Real humans, real responses. Most queries answered within one business day.

Security questions
security@lilesautomation.com
Incident reporting
incident@lilesautomation.com
General / sales
eric@lilesautomation.com

Need an NDA, DPA, BAA, security questionnaire response, or SIG Lite filled out? Email security@lilesautomation.com and we'll turn it around within 3 business days.

Demo hub · Email Eric · Meet Atlas Your data & connected accounts stay isolated — never co-mingled. Every send is opt-out-safe, price-validated & logged. Last updated: June 12, 2026 · © 2026 Liles Automation