Ataccama trust center

Trust Center

Security and compliance are foundational to Ataccama. Our products and operations are designed from the ground up to meet rigorous industry standards, demonstrated by our ISO 27001 and ISO 9001 certifications, and our annual independent SOC 2 Type II assessments. Through transparent global operations, robust cloud security architecture, and responsible AI practices, we protect your data, maintain your trust, and empower you to leverage your data confidently.

Audits and certifications

Audits and certifications
SOC logo
SOC 2 Type II

​​Ataccama undergoes an annual SOC 2 Type II audit, conducted by an independent third-party auditor, to assess the design and operational effectiveness of our controls. This audit evaluates our adherence to the AICPA Trust Services Criteria for security, availability, confidentiality, processing integrity, and privacy, including HIPAA-related controls.

Audits and certifications
SOC logo
SOC 1 Type II

Ataccama undergoes an annual SOC 1 Type II audit conducted by an independent third-party firm to assess the design and operational effectiveness of controls over financial reporting (ICFR). This report evaluates the controls relevant to customers' financial reporting needs across Ataccama's global operations, including our Ataccama ONE platform and associated services.

Audits and certifications
HIPAA logo
HIPAA, 1996

Ataccama aligns with HIPAA requirements to protect Personal Health Information (PHI) under US healthcare regulations. Our SOC 2 Type II audit includes controls mapped to HIPAA security and privacy rules, verifying that we safeguard PHI through robust administrative, physical, and technical measures.

Audits and certifications
ISO 27001 logo
ISO 27001:2022

Ataccama’s Information Security Management System (ISMS) is certified to ISO 27001:2022, the internationally recognized standard for managing information security. This certification demonstrates our commitment to protecting customer data through rigorous security controls, policies, and procedures designed to mitigate risks across people, processes, and technology.

Audits and certifications
ISO 9001 logo
ISO 9001:2015

Our Quality Management System (QMS) is certified to ISO 9001:2015, the leading global standard for quality assurance. This framework ensures that Ataccama consistently delivers high-quality products and services, driven by continuous improvement and customer satisfaction.

Audits and certifications
GDPR logo
GDPR, 2016/679

Ataccama adheres to the General Data Protection Regulation (GDPR), ensuring the protection and privacy of personal data for individuals in the European Union. Our SOC 2 Type II audit includes an independent assessment of controls aligned with GDPR requirements, covering data minimization, access restrictions, transparency, and secure data disposal practices.

Compliance

Compliance
Closing the lineage gap: how Ataccama and Rocket Software deliver true end-to-end lineage

Data lineage has become one of the most critical capabilities in modern data management. It shows where data came from, how it was transformed along the way, and where it ultimately lands. That makes it essential for impact analysis and, more recently, for accurate AI agent reasoning. But lineage carries a hidden condition that's easy to overlook until it bites: it's only useful when it's complete.

Most enterprises don't run on a single, tidy stack. A typical estate spans cloud data warehouses, on-premises databases, streaming platforms, ETL tools, reporting layers, and, in many organizations, decades of mainframe and legacy systems that still power critical business processes. For many enterprises, the lineage challenge begins in these source systems, where customer transactions, financial records, claims, payments, and other operational data originate. Lineage has to stretch across all of it. The moment one of these environments falls outside lineage coverage, the graph fragments, and an incomplete graph can't reliably answer the questions employees, regulators, and AI systems rely on it to answer. That is the gap the Ataccama and Rocket Software integration is built to close.

Lineage breaks when source systems aren’t covered

Ataccama ONE ships with built-in scanners for the platforms most enterprises use every day — Snowflake, Oracle, dbt, Power BI, and many other common technologies. For a large share of modern data environments, that native coverage delivers very strong lineage visibility. The challenge is that most enterprises don't run on modern platforms alone: critical customer, transaction, financial, and operational data often originates in mainframe and legacy environments, and complete lineage requires visibility across that entire journey.

That reliance runs deep. These environments typically support the core business processes enterprises depend on most, so when lineage doesn't extend through them, visibility breaks down right at the source. What looks like end-to-end lineage is often a partial view, with gaps between operational systems and the downstream analytics, governance, and AI platforms that rely on them. For teams using that lineage to validate a regulatory report or trace a data quality issue back to its origin, those gaps introduce risk exactly where certainty matters most.

These gaps translate into real cost, and they land in exactly the places lineage was meant to protect. A figure that can't be traced back to its origin can't be confidently defended to a regulator, which turns a coverage gap into compliance risk with the potential for costly penalties. A pipeline that skips over a disconnected node keeps pushing bad data downstream, and the data team burns hours tracking down where things went wrong. Every time someone hits a blind spot, trust erodes, adoption quietly stalls, and people fall back on the manual tracing the platform was supposed to replace.

That's why completeness isn't a refinement you add later. It's the whole game. Complete, accurate, end-to-end lineage is the difference between a lineage project people trust and one they quietly work around.

Rocket Software as a native lineage source

To close that gap — and make sure lineage is genuinely traced end to end, with every system in the enterprise estate covered — Ataccama partners with Rocket Software to extend the reach of its lineage scanners into the mainframe and distributed systems where much of that critical customer, transaction, financial, risk, and operational data originates. But the value goes beyond making mainframe and legacy systems visible in the lineage graph. The real gain is connecting those systems to downstream cloud, analytics, and AI platforms, and understanding how data moves across the entire ecosystem.

Within Ataccama ONE, Rocket's scanners function as fully supported lineage sources. That's the important part: with native integration, lineage metadata from Rocket is indistinguishable from lineage produced by Ataccama's own scanners. Both appear in the same graph and the same interface, governed by the same platform, and benefit from the same enrichments — data quality overlays, transformation context with AI-generated explanations, metric calculation breakdowns, and more. The people consuming it don't need to know where it came from. They just see a complete picture.

How it works

Behind that unified experience, the integration architecture is deliberately loosely coupled. There's no direct runtime connection between Rocket's scanners and Ataccama ONE, which better suits the restricted, security-conscious environments where these systems typically live.

From the user's perspective, Rocket is configured like any other lineage source, with its own scan plan. When a scan runs, Ataccama's Edge Lineage Scanner — running inside the customer's own environment — triggers the Rocket scan, collects the results as a standard Ataccama lineage package, and propagates that metadata to Ataccama exactly as it would for any built-in scanner. The exchange happens through a well-defined, file-based contract, which keeps the boundary clean and the deployment predictable.

The result is one lineage graph with a materially wider reach.

The coverage this unlocks

The practical value of the integration is the breadth of data sources it brings into the lineage scope. Two broad categories are worth highlighting.

Lineage for distributed and non-mainframe technologies, including but not limited to:

  • Informatica and IBM DataStage
  • Teradata (and Teradata SQL scripts)
  • Kafka and the Java Kafka API
  • MongoDB, MySQL, and PostgreSQL / Greenplum / Redshift
  • MicroStrategy and MS SSRS
  • Python, DB2 (non-mainframe), and SAS

Lineage for mainframe and legacy systems, including but not limited to:

  • COBOL for z/OS, CICS, JCL, Db2 for Z, and Assembler for z/OS
  • IMS (DB and DC), ADABAS, NATURAL, and CA-IDMS/DB
  • IBM MQSeries and scheduling tools such as Control-M and CA-Autosys
  • The AS/400 family: RPG, COBOL, DB2 schema and stored procedures, and the library file system

This coverage extends lineage across the technologies where critical operational data originates and the modern platforms where it is analyzed, governed, and consumed. The result is a continuous lineage graph that spans mainframe, distributed, and cloud environments.

Why this integration matters

The benefits come down to three things.

Complete end-to-end lineage. Extending coverage across legacy, distributed, and mainframe technologies closes the gaps that fragment the graph and enables teams to connect and trace data continuously from all source systems through downstream warehouses, analytics platforms, reports, and AI applications.

A single place to consume lineage. The people who use lineage day to day — analysts, stewards, data and application engineers — get one connected picture inside Ataccama ONE without needing to reconcile tools or work out which technology produced which segment.

Faster time to value. Instead of building custom solutions to reach data siloes, customers can draw on Rocket's proven scanning capabilities inside Ataccama today and put complete lineage to work immediately.

What complete lineage lets you do

With the full picture in place, the integration directly strengthens the use cases teams care about most:

Data quality and root-cause analysis. Trace data back to its source, proactively spot broken pipelines, and remediate quality issues before they spread. The payoff is a more efficient data team that spends less time hunting for where things went wrong and more time delivering trusted data to the business.

Trusted reporting and AI. Understand data origins and transformations, and validate calculations end-to-end. When the lineage is complete, the reports — and increasingly the AI — built on top of it are ones the business can actually trust for decisions.

Data governance and compliance. Validate reports before regulatory submission, streamline audits, and demonstrate responsible handling of sensitive data across the full data journey. The result is lower compliance risk and fewer costly surprises.

Pipeline impact analysis. See how a proposed change ripples across systems and downstream consumers before it breaks something, making change management safer and less disruptive.

Data modernization. Plan and execute migrations with clear visibility into legacy data flows, transformations, and dependencies. This is where Rocket's mainframe and legacy coverage is especially compelling. Modernization becomes far less risky when organizations can trace dependencies across mainframe, distributed, and cloud environments and understand how data flows between them before making changes.

Ataccama as the central lineage and governance hub

Most lineage problems in complex enterprises aren't a failure of the platform — they're a coverage gap in a hard-to-reach corner of the estate. The Ataccama and Rocket Software integration is designed to close exactly those gaps, so that Ataccama ONE can serve as the single, central hub for lineage and governance no matter how heterogeneous the underlying landscape is.

To see how Ataccama lineage delivers it end-to-end, explore Ataccama’s lineage capabilities.

Compliance
Statement on AI Vulnerability Management and Emerging Threats

Ataccama has adapted its security program as AI accelerates how vulnerabilities are discovered and exploited. This statement covers how we govern our use of AI, use it to strengthen defenses, and manage vulnerability remediation.

Compliance
Sustainability Report 2025
Compliance
Statement on NIS2 Compliance
Compliance
Statement on the Prevention of Slavery and Human Trafficking
Compliance
ecovadis logo
EcoVadis

Ataccama participates in the EcoVadis sustainability assessment, a globally recognized evaluation of corporate performance across key ESG Environmental, Social, and Governance) areas. Our latest EcoVadis sustainability scorecard is available upon request. Please reach out to your Ataccama sales representative for access.

Compliance
DORA logo
DORA 2022/2554

Ataccama aligns with the Digital Operational Resilience Act to support financial institutions in meeting ICT risk management and operational resilience requirements under EU regulation. We provide audit-ready processes, transparent ICT practices, and secure data governance through our Ataccama ONE platform, ensuring that financial entities can confidently rely on our services as part of their digital resilience strategies.

Compliance
CCPA logo
CCPA, 2018

Ataccama complies with the California Consumer Privacy Act (CCPA), ensuring transparency and control over the personal information of California residents. We uphold core CCPA principles such as the right to access, delete, and opt out of the sale of personal data.

FAQ

We take a proactive, risk-based approach to security, privacy, and compliance across all areas of our business. Our internal processes are aligned with industry best practices and continuously evolving to meet customer and regulatory expectations.

We implement a combination of technical and organizational measures to ensure the confidentiality, integrity, and availability of customer data across our systems and operations.

Ataccama performs annual independent audits (SOC 2 Type II, ISO 27001, ISO 9001) and conducts continuous vulnerability scans, regular penetration tests, and security patching as part of our vulnerability management program.

Certifications (ISO 27001, ISO 9001) and publicly shareable compliance documents are directly accessible from our Trust Center. Confidential documents, such as our SOC1/SOC 2 Type II reports are available upon request through your Ataccama representative.