Attri Trust Center
Transparency, security, and policies that guide how we protect your data and deliver our services
Attri Security Addendum
Updated: April 6, 2026
Transparency, security, and policies that guide how we protect your data and deliver our services
Updated: April 6, 2026
Attri has implemented a comprehensive security, compliance and privacy management program under which Attri maintains industry standard physical, administrative, organizational and technical safeguards designed to protect the confidentiality, integrity, availability, and security of the Services and Customer Data, including the measures set forth herein (the "Security Program"). Attri regularly tests and evaluates its Security Program and may review and update its Security Program as well as this Attri Security Addendum from time to time including to take in account technological developments, provided, however, that such updates shall be designed to enhance and not materially diminish the Security Program.
1. IaaS and hosting.
1.1. IaaS Provider. Attri's Platform is hosted on AWS.
1.2. Hosting location. Attri offers hosting in several locations including in the US, the EU and the UK. Customer may select the region in which their Attri tenant will be hosted prior to the tenant being created.
2. Attri's Audits & Certifications.
2.1. Certifications. Attri shall be assessed by independent third-party auditors on at least an annual basis under the following audits and certifications ("Third Party Certifications"): SOC2 Type 2, SOC3, ISO 27001, ISO 27701, ISO 27017 and/or ISO 27018. Attri shall make available to Customer such Third-Party Certifications upon Customer's written request. To the extent Attri decides to discontinue a Third-Party Certification, Attri will adopt or maintain an equivalent, industry-recognized framework or standard.
2.2. PCI-DSS. To the extent Attri processes cardholder data in the provision of Services, Attri shall perform a Payment Card Industry Data Security Standard Attestation of Compliance ("AOC") for Service Providers on an annual basis and shall provide such AOC to Customer upon Customer's written request.
3. Encryption.
3.1. Encryption of Customer Data. Customer Data shall be encrypted by Attri in transit (TLS 1.2. or above) and at rest (AES 256).
3.2. Key Management. Attri utilizes AWS' Key Management System (KMS) to encrypt Customer Data. Keys are rotated periodically and are stored only in the KMS in the region of the Customer's Attri tenant.
4. Authentication, Authorization, and Credential Management.
4.1. User Authentication (Attri Employees). Attri enforces user authentication and authorization on Attri systems via Single Sign-on ("SSO") and multifactor authentication ("MFA").
4.2. User Authentication (Customer using Attri). Attri supports SAML 2.0 compliant SSO applications, allowing customers to manage authentication for their own Attri tenant.
4.3. Secure Storage of Credentials. Attri uses managed authentication services (Okta for Attri's employee environment; Amazon Cognito for Attri's software platform) to handle authentication and associated credential management, including encryption in-motion and at-rest for passwords and other forms of credentials. Cloud-native Key Management Systems, such as AWS KMS, are used to store other forms of access tokens and secrets.
4.4. Role-based Access Control (RBAC) for Attri Employees. Access to Attri information assets is restricted, and is granted to Attri employees and contractors in order to fulfill their duties on a need-to-use basis and following the least privilege principle. Attri employees and contractors are not granted access to any information asset that is not required by their work at Attri. Attri has defined various user roles, according to the positions and activities in the company. Each Attri employee and contractor is assigned one of these roles and receives access control privileges relevant to that role. Quarterly reviews for user access will be conducted and access will be immediately revoked for unrequired access.
4.5. Role-based Access Control for Customers using Attri. Attri provides customers with the ability to define roles for their own Attri users that control the information they see and the actions they perform.
4.6. Access to Customer Data. Attri personnel will not access Customer Data except (i) as reasonably necessary to provide the Attri Services under the Agreement; (ii) with Customer's permission; or (ii) to comply with the law or a binding order of a governmental body.
4.7. Minimum password requirements. Attri shall follow the guidance provided by NIST 800-63B Digital Identity Guidelines to enforce password security controls, including length, complexity, re-use, lock-out, and use of multi-factor authentication. Passwords must never be stored in plain-text nor transmitted over unencrypted channels.
4.8. Session lifespan. Single-sign on sessions expire after 8 hours of inactivity with a maximum duration of 12 hours.
5. Workstation and Device Security.
5.1. Session Lock out. End-user devices are set to screen lock and require a password after 15 minutes of inactivity.
5.2. Workstation Security Controls. For access to Attri systems, Attri personnel must use Attri-issued laptops which utilize security controls that include, but are not limited to, (i) disk encryption, (ii) endpoint firewall, (iii) anti-malware and endpoint detection and response (EDR) tools, and (iv) vulnerability management tools in accordance with Section 9.1 (Vulnerability & Detection Management).
5.3. Anti-malware. Attri maintains anti-malware controls to automatically detect and prevent malicious files, user activity, and network activity on Attri workstations, within Attri's e-mail, and within Attri's corporate cloud storage solutions.
5.4. Workstation Management and Hardening. Attri utilizes system management technologies to ensure that all endpoints are appropriately configured, hardened, and patched following Attri's technical procedures and applicable industry standards such as CIS Benchmarks.
5.5. Data Loss Prevention. Attri utilizes Data Loss Prevention (DLP) technologies to monitor and control sensitive information that is stored or accessed on systems. Attri workstations are restricted from using removable storage devices and media.
6. Cloud Infrastructure Security.
6.1. Separation of Environments. Attri's cloud network is divided into three segregated network environments: The development network, the staging network, and the production network. Each of these environments is segregated from the others and has its own privilege allocation and access control. There is no shared network, communication, or co-operation between the networks. Customer Data is never stored or accessed in development environments.
6.2. Infrastructure as Code. Attri's cloud production environments are configured, provisioned, and managed through Infrastructure as Code (IaC), and subject to the controls defined in Attri's Software Development Lifecycle (SDLC).
6.3. Remote Access. Attri enforces device, network, authentication, and resource-specific authorization controls to limit access to development and production environments. Attri does not automatically confer privileged access to any workstations or devices based on location.
6.4. Network Security. Attri utilizes cloud-native network security technologies, including network security groups, Web Application Firewalls, access gateways, application load balancers, and VPC configurations, to restrict ingress and egress traffic in cloud environments to the minimum sets of services and addresses required for business functionality.
6.5. Cloud Infrastructure Hardening. Attri utilizes its own instance of the Platform ("Attri for Attri") in conjunction with cloud-native security services to ensure that cloud resources are configured and secured in accordance with Attri's internal technical procedures and industry standards such as the CIS AWS benchmarks.
6.6. Anti-malware. Attri utilizes Attri for Attri in conjunction with cloud-native security services to detect and respond to potentially malicious activity on its cloud-hosted workloads or networks.
7. Monitoring & Logging.
7.1. Logging. Attri maintains security auditing and logging capabilities for the infrastructure, SaaS applications, and cloud services that support its corporate, development, and production environments in accordance with Attri's Information Security Policies. The use and activity of Attri information assets is logged and audited for suspicious activity. Attri preserves security-related logs for a minimum of 12 months unless otherwise specified in its security policies and procedures.
7.2. Detection and Response Operations. Attri uses Security Information Event Management (SIEM), Detection, and Alert Notification technologies to centralize and analyze logs, apply detection criteria, and escalate and route events to the appropriate security teams.
7.3. Customer Access to Logs. Customers have access to system and user activity logs for their respective Attri tenant via the Platform, and can export these logs to their own log storage or SIEM platforms as described in the Documentation.
8. Security in the development process.
8.1. SDLC. Software development in Attri is performed according to Attri's Change Management & Software Development Life Cycle (SDLC) procedures.
8.2. Security Reviews. Attri conducts security reviews for significant changes, such as major new product features or changes that impact Attri's security posture, during the design and development process.
8.3. Peer Reviews. Code changes must undergo secondary review and approval before being promoted to production.
8.4. Security Testing within the SDLC. Attri uses security technologies to automatically scan for vulnerabilities, exposed secrets, and code security risks as part of the CI/CD pipeline.
9. Vulnerability Detection & Management.
9.1. Vulnerability Detection & Management. Attri shall maintain a continuous vulnerability management process across its corporate and production environments to ensure that vulnerabilities and other threats are quickly identified, prioritized, and remediated. This includes carrying out internal vulnerability tests daily and external vulnerability tests regularly (at least quarterly). Vulnerabilities shall be remediated according to Attri's Vulnerability Management Policy which shall meet or exceed industry standards. Attri uses the Common Vulnerability Scoring System (CVSS) v3.1 and National Vulnerability Database (NVD) ratings as guidelines for patch prioritization and scheduling.
9.2. Penetration Testing. Attri shall engage one or more independent third parties to conduct penetration tests of the Service at least annually and upon major changes to the Services. Attri will provide summary results of penetration tests to Customer upon written request.
10. Administrative & Organizational Controls.
10.1. Personnel Security. All prospective Attri employees go through pre-employment reference and/or background checks, according to the local HR policies and applicable laws.
10.2. Personnel Agreements. All Attri employees and contractors are required to sign a contract which includes a confidentiality obligation and are provided with Attri's security policies, including Attri's Acceptable Use Policy, when their work commences. Any change in an employee's position in Attri or change in his or her access privileges immediately affects the employee's access via the centralized access control system.
10.3. Personnel Training. All Attri employees are required to complete security and privacy awareness training during onboarding and on at least an annual basis.
10.4. Attri Risk Management. Attri maintains a third-party Attri risk management program, which includes a compliance, security, and privacy review for every third-party used in the provision of the Services and/or with access to Customer Data. The results of the risk assessment are reviewed by the security, legal and privacy team to ensure the third party maintains security measures consistent with the measures hereunder.
11. Physical & Environmental Controls.
11.1. Cloud Environment Data Centers. Attri only utilizes leading cloud providers who shall be required to have a SOC 2 Type II annual audit and ISO 27001 certification, or industry recognized equivalent frameworks.
11.2. Attri Corporate Offices. Attri's employees and subcontractors in each of Attri's offices are subject to Attri's physical minimum-security requirements which include use of CCTV with a defined retention period in accordance with applicable laws, badge only access with regular access reviews and requirements for visitors to be logged and accompanied by Attri authorized personnel.
12. Security Incident Notification and Response.
12.1. Attri shall maintain a formal documented Information Security Incident Management Program designed to provide an effective and consistent process for managing security incidents.
12.2. Security Incident notification. In any event of a reasonably suspected or successful unauthorized access, use, disclosure, modification, or destruction of Customer Data ("Security Incident"), Attri will notify Customer within 48 hours of becoming aware of the Security Incident and shall promptly take reasonable steps to contain, investigate, and mitigate such Security Incident. Attri shall provide Customer with assistance and information as reasonably required by Customer in order to fulfil its legal obligations.
12.3. Security Incident Reporting and Response. Security Incidents are reported to Attri's Chief Information Security Officer (CISO). The CISO acts according to Attri's Incident Response Plan in classifying, handling, documenting, and reporting any incident. Customer may request a copy of Attri's Incident Response Plan.
13. Backup, Business Continuity & Disaster Recovery.
13.1. Business Continuity and Disaster Recovery Plan. Attri maintains industry standard business continuity and disaster recovery procedures, as further described in Attri's Business Continuity and Disaster Recovery Plan ("BCDRP"), and will implement these procedures to minimize the impact of events, whether related to technology or operational failures, that may affect Attri's ability to provide the Services. Attri shall provide Customer with its BCDRP upon Customer's written request. Attri's RTO shall not exceed 48 hours.
13.2. Testing of BCDRP. Attri shall conduct testing of its BCDRP at least annually and shall make the results of such testing available to Customer upon written request.
13.3. Backups and Disaster Recovery. Attri leverages multiple Amazon services to backup Customer Data on both daily and monthly schedules. Each Customer tenant is allocated a disaster recovery tenant in a geographically distinct area. Where possible, Attri will use a disaster recovery region in the same jurisdiction as the main data center. Attri also keeps full and incremental backups of critical corporate data and logs in geographically distinct datacenters.
14. Customer Audit Rights. To the greatest extent possible, Customer shall utilize Attri's Third-Party Certifications and other security documentation and policies to assess Attri's compliance with its obligations hereunder. Only to the extent that Customer is not able to do so, and in any event, no more than once per year except if required by applicable law, and following at least 45 days' notice in writing from Customer, Attri shall provide Customer (and/or Customer's third party advisors who are not reasonably objected to by Attri and who are subject to appropriate confidentiality obligations) with access to documents, systems, Attri employees and electronic data as reasonably necessary in order to audit Attri's compliance with its obligations under this Addendum. Attri shall provide assistance, co-operation, and access reasonably required by Customer in relation to the conduct of such audits. Customer shall use reasonable endeavors to ensure that the conduct of each audit does not disrupt the Attri's business. In no event shall Customer be permitted to access to any information, including without limitation, personal data that belongs to Attri's other customers or such other information that is not relevant to Attri's compliance with this Addendum. Except as required by law, the Parties shall agree on the scope, methodology, timing and conditions of such audits in advance.
15. Shared Responsibility. Without derogating from Attri's obligations hereunder, Customer acknowledges that it is responsible for implementing, running and managing the Platform on a day-to-day basis. In addition, Customer acknowledges and agrees that it has obligations with respect to the security of the Customer Data and the Services. Customer's responsibility includes but is not limited to: (i) the security of cloud environments it owns, operates, and connects to Attri, and for configuration of its instance(s) of the Attri Platform; (ii) provisioning Permitted Users with access to Customer's instance of the Attri Platform, including: (a) managing instance-level administrators and other user privileges; (b) deauthorizing Permitted Users who no longer need access; (c) provisioning and configuring service account or API access; (d) enabling integrations with customer-owned or third-party technologies; and (e) ensuring that all Permitted User's keep all Attri credential's confidential; and (iii) updating any Attri provided software upon Attri's announcement of such updates. Attri provides customers with audit logs that record customer user account and application activity occurring within their respective Attri Platform instance(s), however, Customer is responsible for monitoring its own instance's audit logs for security or other purposes. Customer agrees to notify Attri upon becoming aware of any reasonably suspected unauthorized access to the Platform.