Security
Powerful enough to act. Designed so you stay in control.
An assistant that can see your calendar, email, messages, location, home and car raises an obvious question. Atlas is built to answer it before you ask.
"You're giving this thing access to everything."
Correct — and that's exactly why control and traceability are part of the product, not an afterthought. Breadth is only an asset if you stay in charge of it.
The principles
Four commitments Atlas is built around.
You control what Atlas can see.
You control what Atlas can do.
Important actions require approval.
Every action can be traced.
Tenancy
Not an account. An installation.
The part most people have no reference point for — because nothing else they use works this way.
Almost every service keeps everyone’s data in one system and puts walls between you. The walls are usually good. But the system is shared, so the walls have to hold — forever, against every bug and every mistake.
Atlas doesn’t have that system. Each Atlas is its own application, with its own database, running on its own. There is no shared store, no customer table, no console that looks across users — because there is no “across users.” Another installation could fail, or be broken into, and yours would never know it happened.
Atlas is private because of how it is built, not because of a setting. There is no configuration that turns this off, and no growth milestone that quietly changes it. Isolation isn’t a feature of Atlas; it’s the shape of it.
What that means in practice
The model is generic. Your Atlas is not.
Atlas does not train on your data — it does not train at all. It calls the same off-the-shelf model everyone else calls, and that model forgets you the moment it answers. What makes your Atlas different is everything around it: what it knows about your people, your places, your habits, the promises you’ve made. That lives in your installation, and nowhere else.
Which is why every Atlas ships identical, and none of them stay that way. Two people who install on the same morning end up, within weeks, with two different assistants — yours has been learning your world, theirs has been learning theirs. Nothing you tell Atlas makes anyone else’s smarter.
It doesn’t get better for everyone. It gets better for you.
The architecture
How that's enforced.
Single authorized owner
Each installation serves exactly one owner. Atlas acts only on their behalf — there's no shared, multi-user surface over one person's data.
Server-side & encrypted
Account tokens and secrets are stored encrypted, kept server-side, and never exposed in the interface or to the model.
Human in the loop
Anything that changes the real world — a message, a booking, a device — pauses for your explicit approval before it runs.
Untrusted content, contained
Content from emails, web pages and messages is treated as data, not instructions — so a message can't quietly redirect Atlas to act against you.
Guarded outbound fetches
Requests Atlas makes on your behalf are constrained to prevent them from being pointed at internal or unintended targets.
Signature verification
Inbound webhooks and events are verified before they're trusted, so external systems can't spoof activity into your Atlas.
Secrets isolation & rate limits
Secrets are compartmentalized and requests are rate-limited, reducing blast radius if any single surface is stressed.
Traceable activity
What Atlas did, when, and why is recorded — so you can review every action after the fact.
Revoke access anytime
Disconnect any service in a click. Atlas stops accessing it and drops the associated credentials.
Honest about maturity
The right architecture — and what it hasn't earned yet.
Everything above is how Atlas is built. Being straight about what that has — and hasn't — independently proven is part of the same commitment.
Private early access
Atlas is single-owner software, built and stress-tested around one person and now being provisioned for others. It is not a years-in-production platform, and we won't pretend otherwise.
Self-instrumented, n=1
Our reliability numbers are measured, but self-reported and owner-gated — read the Benchmark. Treat them as an honest self-assessment, not a third-party verdict.
No external audit yet
There is currently no independent security audit and no SOC 2 report. Both are on the roadmap as Atlas opens up — we'll say so plainly when they exist, not before.
"Can I connect my work accounts?"
Not yet — and we'd rather tell you so. Atlas today is personal, single-owner software. It is not ready for corporate or regulated data, and it doesn't yet meet the controls a security team will rightly ask for: OAuth-scope review, data-retention terms, a subprocessor list, a DPA, defined incident response, and SOC 2. Connect your personal accounts first. When Atlas can satisfy an organization's bar, we'll document exactly how — until then, keep work email, Teams, and SharePoint out of it.
How to adopt it
Start small. Expand as it earns it.
You shouldn't hand Atlas your whole life on day one — and you don't have to. The sensible path is staged.
See the signal
Connect a calendar and a few read-oriented services. Live with the daily brief, the Executive Brain, and the Life Graph for a couple of weeks — decide whether it's genuinely useful before it can change anything.
Approval-gated actions
Turn on messaging, reservations, replies, and calls. Every real-world action still pauses for your explicit yes before it runs.
The full picture
Add location, home, and vehicle once the rest has earned your trust — the cross-system awareness that makes Atlas an operating layer, not a chatbot.
Addressing the objection makes the breadth of Atlas feel more impressive, not less. An assistant you can trust with your whole world is a different category from a chatbot you keep at arm's length.