Trust
Atlas is an all-in-one work platform built with enterprise governance from day one. This page explains how we protect your data, which security controls Atlas has today, and how your teams get one identity and one audit log across every module.
Last updated: 8 October 2026
Security is built into Atlas, not added later. Every workspace runs on the same controls from the day it is created.
This page lists those controls and says plainly what is and is not in place. You can read a more technical overview at /security.
Atlas does not yet hold a SOC 2 or ISO 27001 certification, and it is not offered for data covered by HIPAA. We will publish any certification here, with its date, when it is issued.
Atlas helps you through your own audits. The Compliance page maps your workspace to SOC 2 and ISO 27001 controls and generates evidence packs from the activity Atlas records: access, role changes, provisioning, and the audit log.
All traffic to and from Atlas is encrypted in transit with TLS. Our database and file storage encrypt data at rest.
Files are private by default and are shared through short-lived signed links. Keys you add for AI providers are never stored in plain text and are never shown again after you save them.
Atlas gives you one identity that works across every module, with controls to govern who can access what.
Atlas records sign-ins, role changes, data exports, billing changes, and other privileged actions in one audit log that spans every module.
Each entry is chained to the one before it, so a removed or altered entry can be detected. Administrators can export the log for their own retention and review.
Administrators can record the region their workspace data should live in and the transfers they allow, with an audit trail of each change. Moving a workspace to another region is arranged with our team on request.
For more on how Atlas supports European data protection obligations, see /legal/gdpr.
For the content your organization creates and stores in Atlas, we act as a processor and handle that data only on your instructions and in line with our agreements.
Our Data Processing Addendum is available at /legal/dpa-request, the current list of sub-processors is published at /legal/sub-processors, and our privacy policy is at /legal/privacy.
Enterprise plans include a 99.95% monthly uptime commitment with service credits, set out at /legal/sla. You can follow live and past availability at /status.
Writes carry idempotency keys, so a retried request never applies twice, and every workspace has its own rate limits.
We welcome reports from security researchers and treat responsible disclosure as a partnership. If you believe you have found a vulnerability, please email security@wrxstack.com with the details.
More information about our program and scope is available at /security/bug-bounty.
Much of Atlas's intelligence runs on your device, and nothing leaves it. When you choose an outside AI provider, Atlas uses the keys you add and the provider you pick, and you can point Atlas at your own model server instead.
We are glad to support your security review. We can complete your security questionnaire and walk your team through the controls on this page.
To start, email security@wrxstack.com or enterprise@wrxstack.com and let us know what your team needs.
Questions about this page? Email security@wrxstack.com or visit our contact page.