Information Security Policy
Last updated on
September 10, 2026
PURPOSE
ATLAS CO-PILOT LTD’s Information Security Policy has been developed to: establish a general approach to information security and the minimisation of information misuse, compromise or loss; document how the company collects, uses, shares, and protects personal data; document security processes and measures; uphold ethical standards and meet the company’s regulatory, legal, contractual, and other obligations; control business risk; and ensure that the appropriate company image and reputation is presented.
SCOPE
This policy applies to:
• Information in any form, regardless of the media on which it is stored, as well as any facility, system, or network used to store, process, and/or transfer information.
• Personal data of customers, users, and other individuals processed through Fluide and Atlas Copilot, including the company’s websites, apps, and related services (the “Service”).
• All ATLAS CO-PILOT LTD employees, temporary staff, partners, contractors, vendors, suppliers, and any other person (collectively also referred to as "Staff"or “Personnel”) or entity that accesses the company’s networks or any other public or private network through company’s networks or systems.
• All activity while using or accessing the company’s information or information processing, storage, or transmission equipment, while on the company premises (owned, rented, leased, or borrowed) or remotely.
• Information resources entrusted to the company by any entity external to the company (i.e. Customers, Staff and others).
• Documents, messages, and other communications created on or communicated via the company systems are considered the company’s business records and, as such, are subject to review by third parties in relation to audits, litigation, process improvement, and compliance.
ATLAS CO-PILOT LTD is the data controller for personal data processed through the Service. Where access is provided by an employer or another organization, that organization may also be a controller for some of that data. The public statement of these privacy commitments is published at Privacy Policy.
PERSONAL DATA COLLECTION
The company collects only the personal data needed to provide the features in use:
• Account information. Name, email address, job title, company, and account credentials when an account is created.
• Content. Messages, prompts, and other text entered; voice recordings when voice chat is used; and files, images, or other attachments uploaded. Voice is collected only after a voice session is started. Uploads are collected only when they are attached.
• Communication information. Name, contact details, and message content when someone emails or otherwise contacts the company.
• Usage and log data. Features used, actions taken, timestamps, and technical logs needed to operate and secure the Service.
• Device information. Device or application type, operating system, and similar identifiers sent when the Service is used.
• Location and time. General area inferred from the connection, plus timezone, local time, and date when needed to personalize or secure the Service. Precise GPS location is not collected.
• Cookies and similar technologies. Used to operate the Service, keep users signed in, and understand usage, as described in the Cookie Policy.
• Organization data. Account, role, or workspace information received when someone joins through an employer or team.
• Service-provider data. Status or fraud-prevention information from payment, security, and analytics providers needed to run the Service.
USE OF PERSONAL DATA
Personal data is used to:
• Provide, maintain, and analyze the Service, including generating replies and processing voice.
• Personalize learning pathways, recommendations, feedback, and conversation context.
• Improve the Service and understand how it is used, including through de-identified or aggregated analytics.
• Communicate about the Service, including support and important account notices.
• Prevent fraud, abuse, and misuse, and protect the security of users and the Service.
• Meet legal, accounting, and safety obligations.
De-identified or aggregated data that no longer identifies an individual may be used for the purposes above. The company does not try to re-identify that data unless required by law.
The company does not sell personal data. It does not use or share it for advertising, marketing on third-party platforms, or advertising-related profiling. It does not share it with third parties for their own marketing. It does not use Content to train its own general AI models.
The Service is not directed to children under 13, and the company does not knowingly collect personal data from children under 13. If a child under 13 has provided personal data, contact support@fluide.ai. Users under 18 should have permission from a parent or guardian.
SHARING OF PERSONAL DATA
Personal data is shared only as needed to run the Service. Each recipient is required to keep it confidential and to provide the same or equal protection as the company applies to it.
OpenAI is used as a data processor to generate replies, process voice, and personalize the experience. With the user’s permission, OpenAI is sent the data needed for the request, which may include:
• Content (messages, including prior turns in the same conversation; voice recordings; uploads).
• Context used to personalize replies, such as name, email, job title, company, saved preferences, timezone, organization or workspace information, and retrieved learning material.
OpenAI receives this data solely to perform that processing on the company’s behalf. It is required not to use it to train its general models or retain it beyond what is needed to deliver the feature and for short-term safety, abuse, and quality monitoring. OpenAI does not sell this data and does not use it for advertising. Nothing is sent to OpenAI until the user taps Continue on the in-app permission screen. Permission can be withdrawn in Settings → AI data, after which further Content or context will not be sent to OpenAI. OpenAI’s practices are described in the OpenAI Privacy Policy.
The company also uses:
• PostHog, to measure product usage and improve the Service.
• Cloud hosting providers, to store and deliver the Service.
• Payment providers, including Stripe, when paid features are purchased.
Those providers receive only the data needed for their function. They process it on the company’s instructions and are not permitted to sell it or use it for advertising.
Personal data may also be shared:
• With the user’s organization. If a work email or organization account is used, administrators may see that an account exists and limited account or usage information needed to manage access.
• For legal reasons. If required by law, or to protect the rights, safety, or property of users, Fluide, or others, including to detect fraud or a serious security issue.
• In a business transfer. If the company is involved in a merger, acquisition, or similar transaction, personal data may be transferred as part of that transaction, still subject to this policy.
• At the user’s direction. If the user chooses to share a conversation, pathway, or other content with someone else.
The company and its providers, including OpenAI, may process personal data in the United Kingdom, the European Economic Area, the United States, and other countries. Where personal data is transferred internationally, legally valid transfer mechanisms are used and the protections in this policy apply wherever the data is processed.
PERSONAL DATA RETENTION
Personal data is kept only as long as needed to provide the Service or for other legitimate purposes such as security, dispute resolution, or legal compliance. How long it is kept depends on the type of data, how it is used, and the individual’s choices.
• Until deleted. Account details, Content, preferences, and similar account data are kept while the account is active.
• After a deletion request. The account is marked for closure and permanently deleted after a 30-day buffer, unless cancelled during that period. An audit record of the request may be kept to show compliance.
• OpenAI. Request data is kept only as needed to deliver the feature and for short-term safety, abuse, and quality monitoring.
• Security logs. Up to 90 days, unless a longer period is needed to investigate abuse or a security incident.
• Billing and transaction records. Up to 7 years where the law requires it.
• De-identified analytics. May be kept for product reporting.
When setting these periods the company considers why it has the data, how sensitive it is, the risk of keeping it, and any legal duty to retain or delete it.
INDIVIDUAL CONTROLS AND RIGHTS
Individuals can:
• Withdraw or restore permission to share data with OpenAI in Settings → AI data.
• Delete their account in Settings → Profile → Delete Account, on the in-app /request-deletion page, or by emailing support@fluide.ai. There is a 30-day buffer before permanent deletion.
• Update name and similar account information in Settings.
• Manage cookies as described in the Cookie Policy.
Withdrawing AI permission stops new sharing. It does not delete data already held. Account deletion is required for that.
Depending on where they live, individuals may also have the right to access their personal data, correct or update it, delete it, restrict how it is processed, receive a copy in a portable format, withdraw consent where the company relies on consent, and lodge a complaint with their local data protection authority.
To exercise these rights, use the controls above or contact support@fluide.ai or hello@atlascopilot.com. Identity may need to be verified before a request can be completed.
BACKGROUND
This policy is the overarching policy over the rest of the security policies, which make up the company’s information security program (ISP). The series of security policies includes:
• Privacy Policy
• Acceptable Use Policy
• Asset Management Policy
• Backup Policy
• Business Continuity/Disaster Recovery Plans
• Code of Conduct
• Data Classification, Retention, and Protection Policies
• Encryption and Password Policies
• Incident Response Plan
• Physical Security Policy
• Responsible Disclosure Policy
• Risk Assessment Policy
• Software Development Life Cycle Policy
• System Access Management Policy
• Vendor Management Policy
• Vulnerability Management Policy
INFORMATION SECURITY OBJECTIVES
It is the policy of ATLAS CO-PILOT LTD that information, as defined hereinafter, in all its forms–written, spoken, recorded, electronically or printed–will be protected from accidental or intentional unauthorized modification, destruction or disclosure throughout its life cycle. This protection includes an appropriate level of security over the equipment and software used to process, store, and transmit that information. Ultimately, the information security goal of ATLAS CO-PILOT LTD is to maintain the following:
• Confidentiality: data and information are protected from unauthorized access
• Integrity: Data is intact, complete and accurate
• Availability: IT systems and platforms are available when needed
ATLAS CO-PILOT LTD’s information security objectives, consistent with the company’s information security program, are:
To protect information from all internal, external, deliberate, or accidental threats;
• To enable secure information sharing;
• To encourage consistent and professional use of information;
• To ensure clarity about roles and responsibilities associated with protecting information;
• To ensure business continuity and minimize business negative impact; and,
• To protect the company from legal liability and the inappropriate use of information.
ROLES AND RESPONSIBILITIES
The Security Officer i responsible for:
- The design, development, maintenance, dissemination, and enforcement of the items contained in this policy and other ISP policies.
- Ensuring that the information security management system conforms to the requirements of ISO/IEC 27001:2013.
- Reporting on the performance of the information security program to top management.
The objectives and measures outlined by the ISP policies shall be maintained and enforced by the roles and responsibilities specified in each policy and related company documents (e.g.,Skills Matrix).
POLICY REVIEW
At a minimum, annually, a security and/or compliance committee composed of senior management and key personnel must discuss, evaluate and document the company’s ISP, ensuring strategic goals and objectives are continually being developed.
At a minimum annual basis, all ISP policies must be reviewed, modified and/or edited to meet necessary security standards. All policies must be signed and approved by authorized management
ACCESSIBILITY
Policies and/or procedures must be accessible to employees for review via the compliance automation SaaS, Drata. Policies pertaining to positions must be reviewed and signed upon hire and on an annual basis by all employees.
EXCEPTIONS
ATLAS CO-PILOT LTD’s Executive Management must approve requests for exceptions to any policies included within the ISP after proper review. Any approved exceptions will be reviewed annually.
**P****OLICY **
Training
Management shall ensure that employees, contractors and third-party users:
• Are properly briefed on their information security roles and responsibilities before being granted access to covered information or information systems;
• Are provided with guidelines which state security expectations of their role within the organization;
• Are regularly notified of security changes and updates, as well as reminded of security responsibilities to be undertaken via annual security awareness training and annual policy acknowledgements;
• Are motivated and comply with the security policies of the organization;
• Achieve a level of awareness on security relevant to their roles and responsibilities within the organization;
• Conform to the terms and conditions of employment, which includes the organization’s information security policy and appropriate working methods.
All new hires must complete information security awareness training as part of their new employee onboarding process and annually after that. New hire onboarding will be completed within 14 days after the date the employee or contractor is hired. Ongoing training will include security and privacy requirements as well as training in the correct use of information assets and facilities.
In addition, consistent with assigned roles and responsibilities, incident response and contingency training to personnel will be done:
• within 90 days of assuming an incident response role or responsibility;
• as required by information systems or policy changes and
• annually.
The organization will properly document that the training has been provided to all employees. All employees must acknowledge in writing their understanding of the Information Security
Program, which includes a Code of Conduct upon hire and annually after that.
The organization will properly communicate to its workforce and, if appropriate, contractors:
• Security updates, changes, and incidents, as needed, via email or appropriate Slack channels.
• Reminders for security responsibilities as part of the annual security awareness training.
Clean Desk/Work Area
Authorized users will ensure that all sensitive/confidential materials, hardcopy or electronic, are removed from their workspace and locked away when the items are not in use, or an employee leaves his/her workstation. This will also increase awareness about protecting sensitive information. As such:
• Employees must ensure that all sensitive/confidential information, hardcopy or electronic, is secure in their work area at the end of the day and when they are expected to be gone for an extended period.
Computer workstations must be locked when the workspace is not in use and must be shut down completely at the end of the day.
Sensitive information must be removed from the desk and securely stored when the desk is unattended and at the end of the day.
Laptops and other portable computing devices must be properly stored/secured.
File cabinets containing Restricted or Sensitive information must be kept closed and locked when not in use or unattended.
Keys used to access Restricted or Sensitive information must not be left at an unattended desk.
Passwords may not be left on sticky notes posted on or under a computer, nor may they be left written down in an accessible location.
Printouts containing Restricted or Sensitive information should be immediately removed from the printer.
Upon disposal, Restricted and/or Sensitive documents should be shredded in the official shredder bins or placed in the locked confidential disposal bins.
Whiteboards containing Restricted and/or Sensitive information should be erased.
Treat mass storage devices such as external hard drives or USB drives as sensitive and always secure and encrypt them.
All printers and fax machines should be cleared of papers as soon as they are printed;this helps ensure that sensitive documents are not left in printer trays for the wrong person to pick up.
Internet/Intranet Access and Use
Use of ATLAS CO-PILOT LTD computers, networks, and Internet access is a privilege granted by management. It may be revoked at any time for inappropriate conduct carried out on such systems,including, but not limited to:
Sending chain letters or partiipating in any way in the creation or transmission of unsolicited “spam” that is unrelated to legitimate Company purposes;
Engaging in private or personal business activities, including excessive use of instant messaging and chat rooms;
Accessing networks, servers, drives, folders, or files to which the employee has not been granted access or authorisation from someone with the right to make such a grant;
Making unauthorised copies of Company files or other Company data;
Destroying,deleting,erasing,or concealing Company files or other Company data, or otherwise making such files or data unavailable or inaccessible to the Company or to other authorised users of Company systems;
Misrepresenting oneself or the Company;
Violating the laws and regulations of federal, state, city, province, or local jurisdictions in any way;
Engaging in unlawful or malicious activities;
Deliberately propagating any virus, worm, Trojan horse, trap-door program code, or other code or file designed to disrupt, disable, impair, or otherwise harm either the Company’s networks or systems or those of any other individual or entity;
Using abusive, profane, threatening, racist, sexist, or otherwise objectionable language in either public or private messages;
Sending, receiving, or accessing pornographic materials;
Causing congestion, disruption, disablement, alteration, or impairment of Company networks or systems;
• Using recreational games; and/or
Defeating or attempting to defeat security restrictions on company systems and applications.
Such access will be discontinued upon the termination of employment, completion of the contract, end of service of non-employee, or disciplinary action arising from violating this policy.If a job function changes and/or transfer, the original access code will be discontinued,only reissued if necessary, and a new access request is approved.
All user IDs that have been inactive for thirty (30) days will be revoked. The privileges granted to users must be reevaluated by management annually. In response to feedback from management, systems administrators must promptly revoke all privileges no longer needed by users.
Teleworking Requirements
Secure remote access must be strictly controlled with encryption (i.e., Virtual Private Networks (VPNs)) and strong pass-phrases.
Authorized Users must protect their login and password without exception.
·While using a ATLAS CO-PILOT LTD-owned computer to connect to the company’s network remotely, authorized users must ensure the remote host is not connected to any other network at the same time, except for personal networks that are under their complete control or the complete control of an authorized user or third party.
·The most up-to-date antivirus software must be used on all computers. Third-party connections must comply with requirements as stated in the Vendor Management Agreement.
Equipment connected to ATLAS CO-PILOT LTD’s networks must meet the requirements for remote access and device use.
Remote Access Tools
All remote access tools used to communicate between ATLAS CO-PILOT LTD assets and other systems must comply with the following policy requirements:
• Multi-factor authentication (such as authentication tokens and smart cards that require an additional PIN or password) is required for all remote access tools
• The authentication database source must be Active Directory or LDAP, and the authentication protocol must involve a challenge-response protocol that is not susceptible to replay attacks. The remote access tol must mutually authenticate both ends of the session.
• Remote access tools must support the ATLAS CO-PILOT LTD application layer proxy rather than direct connections through the perimeter firewall(s).
• Remote access tools must support strong, end-to-end encryption of the remote access communication channels.
• All antivirus, data loss prevention, and other security systems must not be disabled,interfered with, or circumvented in any way.
Mobile Endpoint and Storage Devices
Protecting endpoint devices issued by ATLAS CO-PILOT LTD or storing company data is the responsibility of every employee. This pertains to all devices that connect to the company network, regardless of ownership. Mobile endpoint and storage devices are defined to include:desktop systems (in telework environment), laptops, PDAs, mobile phones, plug-ins, Universal Serial Bus (USB) port devices, Compact Discs (CDs), Digital Versatile Discs (DVDs), flash drives, modems, handheld wireless devices, wireless networking cards, and any other existing or future mobile computing or storage device, either personally owned or ATLAS CO-PILOT LTD owned. An inventory of company-owned assets will be properly maintained.
For endpoint devices,
• Company-issued mobile devices will have antivirus and endpoint security pre-installed.
Users must run an online malware scanner at least once a month.
• If browser add-ons are approved and installed, a browser testing tool shall be run to ensure the security of theadd-on.
Mobile endpoint devices must further meet the requirements for use.
For storage devices,
• A risk anaysis will be conducted before the use or connection to the company network unless previously approved.
• Detection of incidents must immediately be reported to the information security team.
• Stolen mobile devices must immediately be reported to the information security team.
Intellectual Property Rights
ATLAS CO-PILOT LTD takes handling and safeguarding of intellectual property very seriously.Intellectual property rights include software or document copyright, design rights, trademarks, patents and source code licenses.
To ensure this, the following procedures will be maintained:
• The software will only be acquired through known and reputable sources to ensure copyright is not violated.
• An asset inventory will identify all assets with requirements to protect intellectual property rights.
• Proof and evidence of ownership of licenses, master disks, manuals, etc., will be maintained.
• A review of the asset inventory will also make sure that only software and licensed products are installed.
Will ensure compliance with terms and conditions for software and information obtained from public networks
Information Security Requirements Analysis & Specifications
ATLAS CO-PILOT LTD will identify its information security requirements by utilising different methods, ensure the results of the identification are documented and reviewed by all stakeholders, and will integrate the requirements and associated processes in the early stages of projects.
Methods
• Policies and regulations
• Threat modeling
• Incident reviews
• Use of vulnerability thresholds
Factors
Level of confidence required towards the claimed identity of users to derive user authentication requirements.
Access provisioning and authorisation processes for business and privileged or technical users.
Informing users and operators of their duties and responsibilities.
• Protection needs of assets, especially regarding availability, confidentiality, and integrity.
• Business processes (e.g., transaction logging and monitoring, non-repudiation requirements).
Other security controls (e.g. interfaces to logging and monitoring or data leakage detection systems).
Employment Terms and Conditions
The following terms and conditions of employment at ATLAS CO-PILOT LTD are the contractual obligations for employees or contactors to safeguard information. They include, but are not limited to:
Signing a confidentiality or non-disclosure agreement (NDA) before access to confidential information and processing facilities.
• Legal responsibilities and rights, particularly concerning intellectual property.
• Responsibilities for the classification of information and management of organisational assets associated with information, information processing facilities and information services handled by an employee or contractor.
• Responsibilities for the handling of information received from third parties.
• Reviewing and agreeing with the security policies of the company.
• Duration of responsibilities beyond the end of employment.
• Actions to be taken for non-compliance with the terms and conditions and the company’s security policies.
Disciplinary Process
ATLAS CO-PILOT LTD’s discipline policy and procedures are designed to provide a structured corrective action process to improve and prevent a recurrence of undesirable employee behavior and performance issues. It has been designed to be consistent with ATLAS CO-PILOT LTD’s cultural values, Human Resources (HR) best practices, and employment laws.ATLAS CO-PILOT LTD reserves the right to combine or skip steps depending on the facts of each situation and the nature of the offense. The level of disciplinary intervention may also vary.Some factors that will be considered are whether the offense is repeated despite coaching, counseling, or training, the employee’s work record, and the impact the conduct and performance issues have on the organization.
Step 1: Verbal Warning and Counseling
This initial step allows the immediate supervisor to schedule a meeting with an employee to address an existing performance, conduct or attendance issue. The supervisor should discuss with the employee the nature of the problem or the violation of company policies and procedures. The supervisor must clearly describe expectations and the steps the employee must take to improve performance or resolve the problem.
Step 2: Formal Written Warning
If the employee does not promptly correct any performance, conduct or attendance issues identified in Step 1, a written warning will become formal documentation of the performance,conduct, or attendance issues and consequences. The employee will sign a copy of the document to acknowledge receipt and understanding of the formal warning. During Step 2, the immediate supervisor and HR representative will meet with the employee to review any additional incidents or information about the performance, conduct or attendance issues as well as any prior relevant corrective action plans. Management will outline the consequences for the employee of his or her continued failure to meet performance or conduct expectations.A formal performance improvement plan (PIP) requiring the employee’s immediate and sustained corrective action will be issued after a Step 2 meeting. A warning outlining that the employee may be subject to additional discipline up to and including termination if immediate and sustained corrective action is not taken may also be included in the written warning.
Step 3: Suspension and Final Written Warning
There may be performance, conduct, or safety incidents so problematic and harmful that the most effective action may be temporarily removing the employee from the workplace. When immediate action is necessary to ensure the safety of the employee or others, the immediate supervisor may suspend the employee pending the results of an investigation. Suspensions recommended as part of the normal progression of this progressive discipline policy and procedure are subject to approval from a next-level manager and HR.
Step 4: Recommendation for Termination of Employment
The last step in the progressive discipline procedure is a recommendation to terminate employment. Generally, ATLAS CO-PILOT LTD will try to exercise the progressive nature of this policy by first providing warnings, a final written warning or suspension from the workplace before proceeding to a recommendation to terminate employment. However, ATLAS CO-PILOT LTD reserves the right to combine and skip steps depending on the circumstances of each situation and the nature of the offense. Furthermore, employees may be terminated without prior notice or disciplinary action. Management’s recommendation to terminate employment must be approved by HR and the supervisor’s immediate manager. Final approval may be required from the CEO.
Performance and Conduct Issues Not Subject to Progressive Discipline
Illegal behavior is not subject to progressive discipline, and potentially, such behavior is subject to be reported to local law enforcement authorities. Theft, substance abuse, intoxication, fighting and other acts of violence at work are grounds for immediate termination.
Enforcement
ATLAS CO-PILOT LTD Management, under the explicit authority granted by the company CEO, retains the authority and responsibility to monitor and enforce compliance with this Policy and other policies, standards, procedures, and guidelines. Monitoring activities may be conducted on an ongoing basis or a random basis whenever deemed necessary by Management and may require investigating the use of the Company’s information resources. The company reserves the right to review any and all communications and activities without notice.
ATLAS CO-PILOT LTD will take appropriate precautions to ensure that monitoring activities are limited to the extent necessary to determine whether the communications or activities violate Company policies, standards, procedures, and guidelines or per normal business processing performance or quality activities. Violating the controls established in this Policy is prohibited and will be appropriately addressed.Disciplinary actions for violations may include verbal and/or written warnings, suspension, termination, and/or other legal remedies and will be consistent with our published HR standards and practices.