Last Updated: August 17, 2026
How we protect data in Marketing Titan, Lead Titan AI, and IT Titan.
Encryption
Data in transit is protected with TLS 1.2 or higher. Data at rest is encrypted using AES-256 or equivalent.
Access control
We operate role-based access control on the principle of least privilege. Multi-factor authentication is required for administrative access. Access is reviewed periodically and revoked promptly when personnel change roles or leave.
Infrastructure
The Services run on encrypted, audited cloud infrastructure. Environments are segmented, and production access is restricted and logged.
Testing
We conduct regular security audits, vulnerability assessments, and penetration testing.
Monitoring and incident response
We maintain audit logging, monitoring, and documented incident response procedures with defined escalation paths. Suspected incidents are escalated to our security team and Data Protection Officer on discovery.
Personnel
Personnel with access to customer data are bound by written confidentiality obligations and receive security and data protection training.
Sub-processor governance
Vendors are assessed before engagement and bound by written agreements imposing protections no less strict than our own. The current list is published at marketingtitan.ai/subprocessors, with 30 days' notice before changes.
Breach notification
If a personal data breach occurs, we will:
- Notify the competent supervisory authority within 72 hours where GDPR or UK GDPR requires it
- Notify affected customers without undue delay, and within 72 hours where the DPA applies
- Report to the Privacy Commissioner of Canada and the Commission d'accès à l'information du Québec where the applicable risk thresholds are met
- Comply with all applicable US state breach notification statutes
Reporting a vulnerability
Send findings to security@marketingtitan.ai.
Please include steps to reproduce, affected endpoints or components, and any supporting material. We aim to acknowledge within 2 business days.
We ask that you: give us reasonable time to remediate before public disclosure; avoid accessing, modifying, or deleting data belonging to others; avoid degrading service availability; and use only accounts you own or have permission to test.
We will not pursue legal action against researchers who follow these guidelines and act in good faith.
We do not currently operate a paid bug bounty programme, but we credit researchers who ask to be acknowledged.
Certifications and reports
Customers can request available audit reports and security documentation under NDA at security@marketingtitan.ai.
Your responsibilities
Security is shared. Please use strong, unique credentials and enable multi-factor authentication; treat API keys as credentials and rotate them if exposed; review team access regularly and remove people who no longer need it; and grant integration scopes narrowly, revoking them when unused.
Contact: security@marketingtitan.ai AtmosAI, Inc., 30 N Gould St, Ste. R, Sheridan, WY 82801
