generated: '2026-07-17' method: searched source: https://help.altimate.ai/datamates/faq/security/ # Compliance posture documented in Altimate's Security & Compliance FAQ. No dedicated # trust.altimate.ai portal was found (probe-security-programs found none), but the FAQ # publishes a named certification and concrete controls. certifications: - SOC 2 Type II compliance: - GDPR posture: soc2: Audited annually for security, availability, and confidentiality controls. gdpr: >- No customer data is stored (metadata-only); DPAs available on request; deletion requests do not need to be propagated to Altimate. infrastructure: AWS private VPC, network isolation, IAM access controls, AWS SSO + MFA for production access. data_handling: >- Customer credentials encrypted locally in IDE secure storage and never transmitted; BYOK sends data directly to the customer's chosen LLM provider; Altimate LLM Gateway retains only anonymized metadata; no customer code/SQL/PII retained; no data used for training. evidence: - source: https://help.altimate.ai/datamates/faq/security/ keywords: [soc 2 type ii, gdpr, byok, private vpc, aws sso, mfa] contact: https://www.altimate.ai/support