Sulayo.

Trust

What we do, and how you can check it

Sulayo is a Dubai product studio, and we would rather tell you exactly what we do than print a badge. Atlas runs on infrastructure operated by Vercel, Neon and Cloudflare, and each of those providers maintains its own SOC 2 Type II attestation covering the services we use. Sulayo has not completed its own SOC 2 or ISO 27001 audit. What follows is the list of controls that are actually in the product today, described plainly enough that your IT team can hold us to it.

Data protection

01

Tenant isolation

Every query is scoped to one organisation through a single shared module, rather than each page deciding for itself. A user with no organisation is given an identifier that cannot match any record, so a missing scope fails closed instead of returning everyone's data.

02

Scoping inside a tenant

Within an organisation, people see only the properties they are assigned to. Group-wide roles exist for cluster and regional managers, so nobody has to be made a system administrator just to see several hotels.

03

Secrets at rest

Single sign-on client secrets, tenant-supplied AI keys and integration credentials are encrypted with AES-256-GCM before they are stored. The decryption key lives in the environment, never in the database.

04

Uploaded files

Attachments go to a private store with no public URL. Permission is checked before any download link is created, so a link cannot be guessed or forwarded to someone without access.

05

In transit

All traffic is served over HTTPS with HTTP Strict Transport Security enabled by the host.

Access control

01

Roles and capabilities

Permissions are checked per capability, not per job title, and organisations can define their own roles. Sensitive areas such as financials are gated on the specific capability rather than on being an administrator.

02

Two-factor authentication

Time-based one-time codes to the RFC 6238 standard, compatible with Google Authenticator, Authy and 1Password. Once enabled for an account, sign-in requires a code.

03

Single sign-on

SAML and OIDC are available on the Enterprise plan. Single sign-on engages only for sign-in addresses matching your configured domain, and password sign-in stays available so an identity provider outage cannot lock you out.

04

API tokens

A token is shown once at creation. Only a hash of the secret half is stored, so a token cannot be recovered from our database, and it can be revoked at any time. Webhook deliveries are signed so you can verify they came from us.

Accountability

01

Audit trail

Creations, updates, deletions, archiving, sign-ins and exports are recorded with the acting person, the record touched, a summary and a timestamp. There is no path in the product for anyone, including us, to edit or delete a tenant's audit entries. The log only grows.

02

Our access to your data

Support staff can enter a tenant to investigate a problem. Doing so requires a written reason, expires automatically after a fixed period, and writes both the start and the end into your own audit log under the real name of the person, not a shared account. You can see every time we have been in your data.

Ask Atlas and your data

01

It can only read

The assistant is given a fixed set of read-only tools. None of them write, change or delete anything.

02

It sees no more than you do

Every tool runs through the same scoping as the rest of the product, using your own permissions. It cannot surface a property you cannot open, and financial tools are offered only to people who already hold that capability.

03

What leaves your tenant

Only the question and the specific records the tools returned for it are sent to the model provider, over their API, for the length of that one request. We do not use your data to train models. You can supply your own provider key instead of ours, in which case the calls are billed to and governed by your own account.

Where your data lives

The companies we rely on to run Atlas. Each processes only what is listed.

ProviderWhat it processesRegion
VercelApplication hosting and private file storage for attachmentsConfirmed per tenant
NeonManaged PostgreSQL database holding all product recordsConfirmed per tenant
Cloudflare R2Alternative private file storage, used on deployments configured for itConfirmed per tenant
ResendTransactional email: alerts, approvals and password resetsConfirmed per tenant
SentryError monitoring. Configured with personal data capture switched off, so request bodies, headers and cookies are not sentConfirmed per tenant
AnthropicAsk Atlas only: the question asked and the records the read-only tools returned for itConfirmed per tenant

Regions are set per deployment. Tell us your requirement and we will confirm the exact region for your tenant in writing before you sign.

What we do not have yet

Stated plainly, because you will ask and because finding out later is worse.

  • No SOC 2 report and no ISO 27001 certificate of our own. Our infrastructure providers hold theirs; we do not hold ours.
  • No contractual uptime commitment. We will not print a percentage we have not agreed to be held to.
  • No third-party penetration test report. We have not commissioned one yet.
  • No published recovery time objective. The database is managed and backed up by our provider, but we have not committed to a restore window in writing.

Security questions

Send a questionnaire, ask for a specific control, or ask us to prove any line on this page. One of the two founders answers, not a support queue.

hello@sulayo.com