You are handing us access to your systems.
So here is exactly what Atlex can and cannot do with it, how one customer’s data is kept away from another’s, what we keep and for how long, and who else is involved.
Read-only by construction
Atlex has no code path that writes to a connected system. The permissions you grant are read-only, so there is no destructive action to misconfigure - and it reads repository structure, never your source.
One customer can't see another
Row-level security in Postgres, an application role that cannot bypass it, and a boot-time assertion that refuses to start the API if it ever could. A cross-tenant request returns 404, not 403.
Credentials encrypted separately
Connector credentials are encrypted with AES-256-GCM before storage, under a key the database never holds, with rotation supported without downtime.
Yours to take, or to delete
Full export on every plan including Free. Disconnect a source and its data goes with it. Delete the organization and the cascade reaches every table.
What Atlex can reach
Keeping tenants apart
Encryption and credentials
What the AI sees
What we keep, and for how long
- Raw snapshots from your sources30 days
- Resource change history12 months
- Sync run history90 days
- Product analytics12 months
- Audit logKept for the life of the organization
- Your graph, insights and incidentsUntil you delete them
Where your data lives
Sub-processors
What our own analytics collects
What you can do at any time
Reporting a vulnerability

Questions before you connect anything?
Ask them first. We would rather answer a hard question now than have you find out later.
