Help Center
Pages

What is your security disclosure and breach policy?

Topic
Security & compliance
Asked by
Security researchers and customers
AdminUpdated Sep 11, 2026

Responsible disclosure. If you believe you've found a security vulnerability, please report it privately to our security team rather than disclosing publicly. Email the address listed on our security page; we aim to acknowledge reports promptly and will keep you updated through remediation.

What Atlas gives you for your own incident response:

  • A partitioned, tamper-evident audit log of security-relevant events (sign-ins, factor changes, role and permission changes, admin actions).

  • Signed webhooks for every event, so you can stream security events into your own SIEM in real time via log streams.

Breach notification. For managed and Enterprise customers, notification timelines and responsibilities are set out in the DPA. Self-hosted operators control their own detection and notification, using the audit log and log streams as the evidentiary record.

Contact sales for the DPA and our security documentation.

We welcome responsible disclosure of vulnerabilities and aim to acknowledge reports promptly. Atlas keeps a tamper-evident audit log and signed webhooks so you have a verifiable record of security-relevant events for your own incident response.

Was this page helpful?
What is your security disclosure and breach policy?