Institutional-grade security and guaranteed compliance
Your management software is your operation's most critical asset. That's why Hermes' cloud architecture is designed around security-by-design principles and strict data segregation.
- ISO 27001:2022
- GDPR compliant
- DORA ready
- 100% cloud-native on AWS
ISO 27001:2022 certification
Our Information Security Management System (ISMS) is audited and certified to the latest version of the international standard, guaranteeing the confidentiality, integrity and availability of all your portfolio information.
Infrastructure, hosting & encryption
Hosting in top-security European data centres (Tier IV). Data encrypted in transit via TLS 1.3 and at rest using AES-256. Strict logical database isolation per client.
100% cloud-native on AWS
Hermes is a fully cloud-native platform on AWS with no legacy dependencies — elastic scaling and high availability. A clear edge over competitors built on legacy infrastructure.
Business continuity & backups
Automated, geo-replicated backups in real time. Business Continuity (BCP) and Disaster Recovery (DRP) plans tested periodically to guarantee minimal RTO and RPO.
GDPR & privacy
Rigorous GDPR compliance. We act as Data Processor under specific DPAs that guarantee personal data is stored exclusively within the European Economic Area (EEA).
DORA alignment
Infrastructure fully adapted to the Digital Operational Resilience Act. We support ICT-provider registration, full transparency in subcontracting chains and complete assistance during supervisory risk audits.

ISO 27001
Málaga, November 4th, 2023 – We are proud to announce that Atrinium achieved ISO 27001 certification for information security management systems, now held under the ISO/IEC 27001:2022 revision, demonstrating the company’s commitment to the highest level of internal compliance and security.
What is ISO 27001?
ISO 27001 is the most internationally recognized standard for information security management, defining comprehensive requirements across areas such as policy, process, records, ownership, risk management, resourcing, and communication.
How did we achieve the certification?
The threat to cyber security is ever-growing. That’s why over the last 18 months, we’ve not only reviewed and improved all our product development processes but also our production infrastructure and our global operational processes.
The certification was then awarded after a rigorous third-party audit by UNITED REGISTRAR OF SYSTEM SPAIN SL, an internationally accredited certification body, that extensively evaluated our work including Atrinium’s policies, procedures, and processes related to information security.
What does this mean for our stakeholders?
Being ISO 27001 certified guarantees that we’ve achieved the highest security level and is a testament to the fact that Atrinium prioritizes data security for its clients, investors, partners, and employees.
It ensures that:
- All data is rigorously protected
- Risks and vulnerabilities are assessed, minimized, and eliminated
- Our software product and infrastructure are robust and secure
- Atrinium has an internal culture of security, so all employees prioritize information security by design
- We demonstrate operational excellence when it comes to our IT, R&D, HR, and information processes
You can download Atrinium’s ISO 27001 certificate (PDF).