Atlas

Security at Atlas

Last updated: May 22, 2026

Atlas connects to the systems that run your business, so security isn't a feature — it's the foundation. This page details how we protect your data across every layer of the product.

Highlights: data encrypted in transit and at rest, strict tenant isolation, no standing employee access to your data, an append-only audit log, and your workspace content is never used to train shared models.

1. Our Approach to Security

Security is foundational to Atlas, not an afterthought. Because our customers connect their most sensitive systems — CRMs, ticketing, finance, code — we build every layer of the product around the assumption that your data must be protected, isolated, and auditable at all times.

This page describes the controls, practices, and commitments that keep your knowledge layer safe. It is written for security teams performing diligence as well as the business owners who trust us with their data.

2. Encryption

All data is encrypted in transit and at rest.

  • •TLS 1.2+ for all data in transit, with modern cipher suites
  • •AES-256 encryption for data at rest
  • •Encryption keys managed by a dedicated key-management service with regular rotation
  • •Secrets and integration tokens stored in an isolated, encrypted vault

3. Access Control and Authentication

Access to Customer Data is tightly restricted and continuously monitored.

3.1 Customer-side controls

Workspaces support role-based access control, least-privilege defaults, and, on Enterprise plans, SSO via SAML and automated provisioning through SCIM.

3.2 Internal controls

Atlas employees do not have standing access to Customer Data. Access is granted just-in-time, scoped to a specific need, logged, and revoked automatically. All internal access requires multi-factor authentication.

4. Tenant Isolation and Data Segregation

Each customer's knowledge layer is logically isolated. Retrieval, memory, and automation are scoped to a single tenant, and we enforce isolation at the application and data layers so one customer's data can never surface in another's workspace. Enterprise customers may request dedicated infrastructure and data residency.

5. Application and Infrastructure Security

We follow secure-by-design and defense-in-depth practices across the stack.

  • •Hosted on major cloud providers with hardened, minimal images
  • •Network segmentation and private networking for sensitive services
  • •Automated dependency scanning and patch management
  • •Infrastructure defined as code and peer-reviewed before deployment
  • •Web application firewall and rate limiting on public endpoints

6. Vulnerability Management and Penetration Testing

We run continuous automated scanning and engage independent third parties for regular penetration tests. Findings are triaged by severity and remediated on defined timelines. We maintain a responsible-disclosure program — report issues to support@atlasknows.io and we will acknowledge within one business day.

7. Logging, Monitoring, and Detection

Security-relevant events are logged centrally, retained, and monitored. We alert on anomalous access patterns and maintain an on-call rotation to respond to potential incidents around the clock. Customer-facing audit logs are available so your team can review activity in your own workspace.

8. Incident Response and Breach Notification

We maintain a documented incident-response plan that is tested regularly. In the event of a security incident affecting Customer Data, we will investigate, contain, and notify affected customers without undue delay and in accordance with applicable law and contractual commitments.

9. AI, Data, and Model Handling

Atlas is built so that using AI does not mean giving up control of your data.

  • •Customer Data is never used to train models made available to other customers
  • •Model providers are contractually bound to zero-retention terms where offered
  • •Retrieval is grounded in your data with source attribution for every answer
  • •Prompt and completion logs are protected under the same controls as other Customer Data

10. Compliance and Certifications

Atlas aligns its program to recognized frameworks and supports customers' regulatory needs.

  • •Actively working toward SOC 2 compliance
  • •HIPAA support with a Business Associate Agreement available
  • •GDPR and CCPA aligned, with a Data Processing Agreement available
  • •Subprocessor list maintained and available on request

11. Business Continuity and Disaster Recovery

We maintain automated, encrypted backups and a tested disaster-recovery plan with defined recovery-time and recovery-point objectives. Critical services are deployed redundantly to withstand the failure of any single component.

12. Personnel and Vendor Security

Employees undergo background checks where permitted and complete security training on hire and annually. We assess the security posture of subprocessors before onboarding and bind them to data-protection obligations consistent with our own.

13. Reporting a Security Issue

If you believe you've found a vulnerability, please email support@atlasknows.io with details and steps to reproduce. We ask that you give us a reasonable opportunity to remediate before any public disclosure. We do not pursue legal action against good-faith researchers who follow responsible-disclosure practices.