Security at Adwix Atlas

Your agency’s customer data is your business. Here is how we protect it.

Tenant isolation

Every agency’s data lives behind database-level row-level security— isolation is enforced by the database itself on every table, on every query, not just by application code. One agency can never read another agency’s leads, customers, bookings or invoices.

Authentication & access

Accounts support two-factor authentication (TOTP) with authenticator apps. Team members get role-based access (owner / manager / agent), owners can deactivate members instantly, and login events are recorded. Public share links (invoices, proposals, vouchers) use long unguessable tokens and expose only customer-facing fields.

Encryption

All traffic is encrypted in transit with TLS (HTTPS), and data is encrypted at rest by our managed database infrastructure. Hardened HTTP security headers are applied across the app.

Payments

Subscription payments are processed by Razorpay, a PCI-DSS compliant processor. Card and UPI credentials never touch our servers — we store only transaction metadata (amount, status, reference).

Backups & reliability

Data lives in a managed PostgreSQL cluster with automated daily backups and point-in-time recovery capability, hosted in the Mumbai region for Indian customers. Errors are monitored continuously, and platform health is public at adwixatlas.com/status.

Your rights over your data

You can export your data (CSV exports across leads, bookings, invoices, payments and GST) at any time, and request full workspace deletion from Settings — see our data deletion policy and privacy policy.

Reporting a vulnerability

Found something? We want to know. Write to support@adwixatlas.com with the details and we’ll respond promptly. Please practice responsible disclosure — don’t access data that isn’t yours.