Security at Atlas
Last updated: May 22, 2026
Atlas connects to the systems that run your business, so security isn't a feature — it's the foundation. This page details how we protect your data across every layer of the product.
Highlights: data encrypted in transit and at rest, strict tenant isolation, no standing employee access to your data, an append-only audit log, and your workspace content is never used to train shared models.
Contents
- 1.Our Approach to Security
- 2.Encryption
- 3.Access Control and Authentication
- 4.Tenant Isolation and Data Segregation
- 5.Application and Infrastructure Security
- 6.Vulnerability Management and Penetration Testing
- 7.Logging, Monitoring, and Detection
- 8.Incident Response and Breach Notification
- 9.AI, Data, and Model Handling
- 10.Compliance and Certifications
- 11.Business Continuity and Disaster Recovery
- 12.Personnel and Vendor Security
- 13.Reporting a Security Issue
1. Our Approach to Security
Security is foundational to Atlas, not an afterthought. Because our customers connect their most sensitive systems — CRMs, ticketing, finance, code — we build every layer of the product around the assumption that your data must be protected, isolated, and auditable at all times.
This page describes the controls, practices, and commitments that keep your knowledge layer safe. It is written for security teams performing diligence as well as the business owners who trust us with their data.
2. Encryption
All data is encrypted in transit and at rest.
- •TLS 1.2+ for all data in transit, with modern cipher suites
- •AES-256 encryption for data at rest
- •Encryption keys managed by a dedicated key-management service with regular rotation
- •Secrets and integration tokens stored in an isolated, encrypted vault
3. Access Control and Authentication
Access to Customer Data is tightly restricted and continuously monitored.
3.1 Customer-side controls
Workspaces support role-based access control, least-privilege defaults, and, on Enterprise plans, SSO via SAML and automated provisioning through SCIM.
3.2 Internal controls
Atlas employees do not have standing access to Customer Data. Access is granted just-in-time, scoped to a specific need, logged, and revoked automatically. All internal access requires multi-factor authentication.
4. Tenant Isolation and Data Segregation
Each customer's knowledge layer is logically isolated. Retrieval, memory, and automation are scoped to a single tenant, and we enforce isolation at the application and data layers so one customer's data can never surface in another's workspace. Enterprise customers may request dedicated infrastructure and data residency.
5. Application and Infrastructure Security
We follow secure-by-design and defense-in-depth practices across the stack.
- •Hosted on major cloud providers with hardened, minimal images
- •Network segmentation and private networking for sensitive services
- •Automated dependency scanning and patch management
- •Infrastructure defined as code and peer-reviewed before deployment
- •Web application firewall and rate limiting on public endpoints
6. Vulnerability Management and Penetration Testing
We run continuous automated scanning and engage independent third parties for regular penetration tests. Findings are triaged by severity and remediated on defined timelines. We maintain a responsible-disclosure program — report issues to support@atlasknows.io and we will acknowledge within one business day.
7. Logging, Monitoring, and Detection
Security-relevant events are logged centrally, retained, and monitored. We alert on anomalous access patterns and maintain an on-call rotation to respond to potential incidents around the clock. Customer-facing audit logs are available so your team can review activity in your own workspace.
8. Incident Response and Breach Notification
We maintain a documented incident-response plan that is tested regularly. In the event of a security incident affecting Customer Data, we will investigate, contain, and notify affected customers without undue delay and in accordance with applicable law and contractual commitments.
9. AI, Data, and Model Handling
Atlas is built so that using AI does not mean giving up control of your data.
- •Customer Data is never used to train models made available to other customers
- •Model providers are contractually bound to zero-retention terms where offered
- •Retrieval is grounded in your data with source attribution for every answer
- •Prompt and completion logs are protected under the same controls as other Customer Data
10. Compliance and Certifications
Atlas aligns its program to recognized frameworks and supports customers' regulatory needs.
- •Actively working toward SOC 2 compliance
- •HIPAA support with a Business Associate Agreement available
- •GDPR and CCPA aligned, with a Data Processing Agreement available
- •Subprocessor list maintained and available on request
11. Business Continuity and Disaster Recovery
We maintain automated, encrypted backups and a tested disaster-recovery plan with defined recovery-time and recovery-point objectives. Critical services are deployed redundantly to withstand the failure of any single component.
12. Personnel and Vendor Security
Employees undergo background checks where permitted and complete security training on hire and annually. We assess the security posture of subprocessors before onboarding and bind them to data-protection obligations consistent with our own.
13. Reporting a Security Issue
If you believe you've found a vulnerability, please email support@atlasknows.io with details and steps to reproduce. We ask that you give us a reasonable opportunity to remediate before any public disclosure. We do not pursue legal action against good-faith researchers who follow responsible-disclosure practices.