Atomic logo

Security Guides

Every request to Atomic is protected by TLS and authenticated with your API key and secret, and every webhook Atomic sends is signed with an HMAC signature you can verify. For most integrations that is all you need.

Some institutions have internal policies that call for additional, certificate-based controls on top of that baseline. The guides below cover the optional security features Atomic supports for those cases. None of them replace your API credentials; each one is an extra layer that is enabled for your account on request.

These features are optional and are configured per customer and per environment. To turn one on, contact your Atomic implementation representative.