Atera for
IT Departments
Save hours every day by automating 99% of your work.


Atera is committed to developing and using AI in a secure, ethical, and trustworthy way. The guiding principles behind Robin and AI Copilot, our autonomous AI agents for IT, are backed by Atera’s certification to ISO 42001, the international standard for AI management systems.Atera is also certified to ISO 27001, 27017, 27018, and 27032, holds SOC 2 Type II certification, and complies with HIPAA and GDPR.
Your prompts (inputs) and completions (outputs), your embeddings, and your training data:
The Azure OpenAI Service is operated by Microsoft as an Azure service; Microsoft hosts the OpenAI models in Microsoft’s Azure environment and the Service does NOT interact with any services operated by OpenAI (e.g. ChatGPT, or the OpenAI API).
The widespread adoption of generative and autonomous AI systems demands that the tech industry adopt strong internal security practices to safeguard users, systems, and data. As an innovation-first company, Atera aims to not only keep pace with leading companies in responsible AI development, but also set a new standard for the IT industry by embedding robust, transparent security principles into our AI.
The AIMS sets our AI policy, assigns clear roles and accountability for AI governance, and drives AI risk and impact assessments across the AI lifecycle, all maintained through continuous cycles of monitoring and improvement. Every feature of Robin and AI Copilot, our autonomous AI agents for IT, is governed by this system, and the sections below describe how it works in practice.
In line with the data governance principles of ISO 42001, your data stays exclusively yours. All AI models used for Robin are hosted on Microsoft Azure OpenAI, ensuring enterprise-grade security, with all customer data stored within the United States and the European Union. Your data is never shared with OpenAI, Microsoft, or used to train any AI models, including Atera’s own. To meet the standard’s requirements for isolation and protection, all customer environments are logically isolated within Azure with no cross-tenant data access, and all data is encrypted both at rest and in transit.
Reflecting the AI risk and impact assessment principles at the core of ISO 42001, every action Robin can take is risk-evaluated before it is allowed to operate in your environment. Atera provides hundreds of built-in actions and diagnostics that are developed, maintained, and rigorously tested by our engineering team, and each one undergoes thorough review and security evaluation to ensure safe operation.
Robin includes multiple layers of real-time protection that put the operational monitoring expectations of ISO 42001 into practice. Microsoft Prompt Shield is the primary filter, blocking abuse, malicious activity, and harmful content before it reaches the AI model. Adding a further layer of governed oversight, a separate AI-as-a-judge mechanism, an independent AI model with no stake in the conversation, reviews Robin’s outputs to ensure they align with expected behavior. These layers are always on and cannot be disabled, ensuring interactions stay compliant and professional.
Upholding the data management principles of ISO 42001, each customer’s knowledge base, scripts, logs, and configurations are logically isolated within Azure, ensuring no cross-tenant data access. For MSPs, data is also segmented per end-customer, keeping every environment’s boundaries intact.
Consistent with the logging and accountability principles of ISO 42001, every action taken by Robin is recorded in Atera’s Audit Log, just like those performed by human technicians. Each log entry clearly identifies “Robin” as the executing entity, leaving no ambiguity about who or what performed the task. This transparency lets administrators track every change, action, or response generated by the AI agent, holding agent activity to the same rigorous standards of traceability and accountability as any human user.
Extending those same transparency principles of ISO 42001, every interaction between end users and Robin is automatically logged as a ticket in Atera, with all AI decisions recorded as internal comments within the same ticket. These comments are visible only to technicians and admins, giving clear insight into the AI’s reasoning and behavior so IT teams can review context at any time and maintain full oversight and confidence in the agent’s actions.
Putting the responsible-use principles of ISO 42001 into practice, Robin’s behavior is governed by custom instructions, playbooks, and knowledge base articles written by IT administrators in plain language that define the agent’s scope, approval flows, escalation criteria, and guardrails. Robin follows these instructions just like a new technician following your runbook, with all AI operations restricted to predefined IT support boundaries and anything outside that scope escalated rather than acted upon.
In keeping with the human-oversight principles of ISO 42001, AI generated content such as knowledge base articles and script suggestions is always optional and requires manual human admin approval before it is published or executed. No outputs are ever implemented without review.
| Principle | What it means for you | Default behavior |
|---|---|---|
| Privacy-respecting AI | Your information is not used to train external or internal models | Enforced |
| Admin-governed autonomy | Control Robin behavior via Custom Instructions | Fully configurable |
| Risk-rated action control | Actions are risk evaluated before allowed to operate in your environment | Max risk level 2 by default |
| Password reset with 2FA | SMS verification before execution | Enabled |
| Optional AI recommendations | Optional and reviewed before use | Off by default |
| Harmful content filtering | Filters block non-IT and harmful inputs | Always on |
| Tenant/customer data isolation | Segregated databases per tenant/customer | Always enforced |
| Ethical AI commitment | Built on Microsoft Responsible AI standards | Enforced |
| Built on Microsoft Responsible AI standards | All actions logged as ‘Robin’ technician | Always on |
| Conversation and decision logging | All user-AI chats and reasoning logged as tickets/comments | Always on |
Visit us at trust.atera.com or contact our Support team for any specific compliance or security need.













