AtlasWork, planned itself.

    The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

    System status
    • SSO
    • SCIM
    • Two-factor sign-in
    • Audit log

    Product

    • Overview
    • PDF tools
    • Diagram tools
    • People & HR
    • Integrations
    • Marketplace
    • Pricing

    Resources

    • Guides
    • Glossary
    • Compare
    • Docs
    • API reference
    • Support
    • Changelog
    • Status

    Company

    • About
    • Careers
    • Press
    • Contact

    Legal & trust

    • Trust center
    • Security
    • Privacy
    • Terms
    • DPA
    • GDPR
    • SLA
    • Refunds
    • Google API data
    Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
    PrivacyTermsSecurityStatus

    You are in control of your cookies

    Atlas uses strictly necessary cookies to keep you signed in. With your consent, we add anonymized product analytics, conversion attribution, and remembered preferences. Change your mind any time at /privacy/cookies.

    Off until you agree · Change it any time

    • Necessaryalways on
    • Analyticsopt-in
    • Marketingopt-in
    • Preferencesopt-in
    Atlas
    ProductPricingContactGet started

    Trust

    Trust Center

    Atlas is an all-in-one work platform built with enterprise governance from day one. This page explains how we protect your data, which security controls Atlas has today, and how your teams get one identity and one audit log across every module.

    Last updated: 8 October 2026

    On this page

    1. 1. Our security commitment
    2. 2. Compliance and your audits
    3. 3. Data encryption
    4. 4. Identity and access
    5. 5. Auditability
    6. 6. Data residency
    7. 7. Privacy and data processing
    8. 8. Availability and reliability
    9. 9. Responsible disclosure
    10. 10. AI and your data
    11. 11. Security reviews

    Our security commitment

    Security is built into Atlas, not added later. Every workspace runs on the same controls from the day it is created.

    This page lists those controls and says plainly what is and is not in place. You can read a more technical overview at /security.

    Compliance and your audits

    Atlas does not yet hold a SOC 2 or ISO 27001 certification, and it is not offered for data covered by HIPAA. We will publish any certification here, with its date, when it is issued.

    Atlas helps you through your own audits. The Compliance page maps your workspace to SOC 2 and ISO 27001 controls and generates evidence packs from the activity Atlas records: access, role changes, provisioning, and the audit log.

    • Evidence packs for SOC 2 and ISO 27001 audits
    • Data export and deletion on request, to support GDPR rights
    • A published list of sub-processors
    • A Data Processing Addendum on request

    Data encryption

    All traffic to and from Atlas is encrypted in transit with TLS. Our database and file storage encrypt data at rest.

    Files are private by default and are shared through short-lived signed links. Keys you add for AI providers are never stored in plain text and are never shown again after you save them.

    Identity and access

    Atlas gives you one identity that works across every module, with controls to govern who can access what.

    • SAML single sign-on, and sign-in with Google or GitHub
    • SCIM provisioning and deprovisioning
    • Two-factor sign-in with an authenticator app, and backup codes
    • Built-in roles and custom roles, with least-privilege defaults
    • Every workspace isolated from every other at the database level

    Auditability

    Atlas records sign-ins, role changes, data exports, billing changes, and other privileged actions in one audit log that spans every module.

    Each entry is chained to the one before it, so a removed or altered entry can be detected. Administrators can export the log for their own retention and review.

    Data residency

    Administrators can record the region their workspace data should live in and the transfers they allow, with an audit trail of each change. Moving a workspace to another region is arranged with our team on request.

    For more on how Atlas supports European data protection obligations, see /legal/gdpr.

    Privacy and data processing

    For the content your organization creates and stores in Atlas, we act as a processor and handle that data only on your instructions and in line with our agreements.

    Our Data Processing Addendum is available at /legal/dpa-request, the current list of sub-processors is published at /legal/sub-processors, and our privacy policy is at /legal/privacy.

    Availability and reliability

    Enterprise plans include a 99.95% monthly uptime commitment with service credits, set out at /legal/sla. You can follow live and past availability at /status.

    Writes carry idempotency keys, so a retried request never applies twice, and every workspace has its own rate limits.

    Responsible disclosure

    We welcome reports from security researchers and treat responsible disclosure as a partnership. If you believe you have found a vulnerability, please email security@wrxstack.com with the details.

    More information about our program and scope is available at /security/bug-bounty.

    AI and your data

    Much of Atlas's intelligence runs on your device, and nothing leaves it. When you choose an outside AI provider, Atlas uses the keys you add and the provider you pick, and you can point Atlas at your own model server instead.

    Security reviews

    We are glad to support your security review. We can complete your security questionnaire and walk your team through the controls on this page.

    To start, email security@wrxstack.com or enterprise@wrxstack.com and let us know what your team needs.

    Questions about this page? Email security@wrxstack.com or visit our contact page.