Last updated
A public overview of Atlas5’s access controls, booking safeguards, payment provider and compliance work.
Service operator: TPixel, Inc.
Contact: support@trustpixel.ai
Compliance status
Work is underway. These statuses do not represent a completed SOC 2 examination or PCI DSS validation for Atlas5.
Company separation and access
Company data is separated at the database. Access is based on a person’s company membership, assigned role and permissions. Travelers do not get access to a colleague’s trip solely because they work for the same company; booking on someone else’s behalf requires permission.
Work sign-in uses Google or Microsoft. Company setup and booking authority are distinct responsibilities, and an executive confirms their role before the company’s first booking. The company controls membership and is responsible for keeping access current.
The agent and the authorization boundary
The travel assistant works within the company’s configured limits and approval requirements. Rules are checked independently when payment is attempted, even if the assistant already checked them during search. A conversational suggestion does not itself grant payment authority.
Administrators can pause booking in chat. Company approval thresholds and role assignments determine who can authorize an action. On Enterprise, changes to access and company settings are subject to second-administrator review. Other administrators are notified when a new role is granted.
Records that support review
The travel record brings together options presented, rules applied, approvals, payment activity, changes and refunds, with the people and times involved. These records support review of a decision and reconciliation of a trip.
Record access follows company permissions. Retention and deletion requirements, including legal holds and financial records, need to be considered together; deleting account access does not automatically delete the evidence of a booking.
Payments and Coinflow
Coinflow is the listed payment subprocessor for Atlas5. It supports payment processing and related checks. Read the subprocessor notice for its role, information categories and public privacy documentation.
A payment provider’s compliance status does not establish Atlas5’s own status. Atlas5’s PCI DSS work is in progress, as shown above. This overview does not claim that an Atlas5 attestation, audit report or certification has been issued.
Data handling and customer review
The privacy policy explains the information involved in travel requests, bookings, payments and service operation. Customer-specific processing instructions, transfer arrangements, retention obligations and incident-notification commitments belong in the applicable data processing and service agreements.
This public overview describes product controls and the stated compliance status as of the date above. It is not an independent assurance report or a promise of a particular hosting region, recovery time or service level. Existing customers should use their agreed contact for restricted evidence or requirements specific to their organization.