Security
Built to keep your store safe.
This page is maintained by Atlas AI to describe the security controls we have shipped today. It is not an independent certification.
Encryption in transit
All traffic to Atlas AI uses HTTPS/TLS.
Row-level access
Every table enforces workspace-scoped row-level security so data can't cross tenants.
Secret handling
Integration credentials are stored server-side and masked in the UI — never returned in plaintext to the browser.
Auth & sessions
Email/password and Google sign-in with managed sessions. Password reset requires a verified email link.
Least-privilege server functions
All privileged actions go through authenticated server functions, never a direct client-to-database write.
Report a vulnerability
Found something? Email security@atlas.ai — we respond within one business day.
Shared responsibility
Atlas AI runs the platform and enforces the controls above. As a workspace owner, you control who you invite, which integrations you connect, and which AI providers process your prompts. Keep team members and connected accounts up to date from Settings.
Report a vulnerability
We welcome responsible disclosure. Please email security@atlas.ai with steps to reproduce. Do not run automated scans against production accounts.