| Part A — Approved data handled by AtlastixCustomer-approved extracts or uploads and temporary customer-tenancy access support defined engagements; location and retention follow the deployment and agreement |
| Amazon Web Services (AWS) | Applicable Atlastix development, build, delivery or corporate workloads | Depends on the approved workload and configuration | Applicable account, region and service configuration | Assurance follows the contracted service and configuration |
| Microsoft (Azure and Entra ID) | Applicable engineering or approved engagement-data processing; identity services for Atlastix personnel | Depends on the approved Azure workload; personnel identity data in Entra ID | Applicable tenant, deployment and service configuration | Assurance follows the contracted service and configuration |
| GitHub | Source control and CI/CD for product code and customisations; carve-out subservice organisation | Source code and engineering identities — no customer datasets | GitHub.com cloud (United States) | Assurance follows the contracted GitHub service and plan |
| Microsoft 365 | Email, calendar, documents, chat | Business correspondence, customer contact details, support correspondence | Microsoft online services | Assurance follows the contracted Microsoft 365 service and configuration |
| Supporting business suppliers | Team messaging; issue tracking and documentation; payroll and accounting; CRM and marketing; independent testing if commissioned | Customer contact details, engagement and support records, billing details and, if testing is commissioned, scoped vulnerability findings; raw customer datasets are not placed in these tools | Per the register (ATX-SOC-07) | Assurance is reviewed according to supplier risk and recorded internally |
| Part B — AI model providersThe approved product or deployment uses the customer's own provider subscription and keys or the customer's cloud-native model service |
| AI provider for the deployment | AI inference under the approved product or solution design | Content and controls follow the approved purpose, configuration and agreement | Provider, customer environment and agreement specific | The customer's own provider account and cloud-native model service are part of the customer's supplier arrangement and are assessed by the customer; no Atlastix-managed provider receives customer workflow content |
| Part C — In-tenancy deploymentsCurrent delivery is generally in customer- or MSP-controlled cloud tenancies |
| Customer’s or MSP’s own cloud provider | Runs deployed Atlastix products and custom solutions | Production workloads and primary data generally remain under customer or MSP controls. Any extract, upload, temporary access or ongoing integration follows the deployed configuration and agreement. | Customer or MSP tenancy and chosen regions | Contracted by the customer or MSP |
| Part D — Current Device Intelligence customer annexDeployment-specific annex; customer AI provider and keys or customer cloud-native model service |
| Current Device Intelligence deployment | MSP-operated staging deployment undergoing user acceptance testing, with approved engagement support paths; production deployment has not yet commenced | Deployment data stays in the MSP tenancy. Approved extracts or uploads may include personal or end-client data but exclude credentials, tokens and secrets; temporary MSP-tenancy access may be used instead. | MSP tenancy; approved Atlastix copies in Azure Australia East | MSP cloud and AI providers are customer suppliers; Microsoft Azure is the approved Atlastix processor for transferred copies |