Back to Help Center
Credentials

Data security and compliance

2026-07-12 19:10:55

Data security and compliance

heyAtlas follows a layered approach to protect your logistics operation data.

Encryption and secrets

  • API keys and passwords are stored encrypted in the database; never in plain text and never shown again after saving.
  • Credentials are decrypted only while a tool runs, to connect to the target external system.

Company isolation and access

  • Data is isolated per company; one company cannot access another's data.
  • User access is based on roles and permission profiles; sensitive operations are written to the audit log.

Retention and transparency

  • You set your own retention window for business data (messages, runs) between 30–365 days; file attachments have a separate window (30–3650 days).
  • Platform-wide retention policies and the sub-processors in use are shown transparently in the portal (KVKK/GDPR alignment).
  • Financial records with legal retention obligations are independent of these settings.

Approval and human control

  • Risky/irreversible operations can be gated behind human approval in chains and conversations; nothing happens until approved.

After signing in you manage these under Settings → Data and Settings → Credentials.

Was this article helpful?
Didn't find an answer? Open a support ticket