A plain-language overview of security controls currently documented for Atlas Find.
1. Account and session controls
Atlas Find uses authentication controls to associate workspace data with the correct account. The current product also enforces a single-active-session model so a newer sign-in can invalidate a previous active session for the same account.
2. Data access controls
The documented data layer uses row-level access policies and access controls intended to limit records to the appropriate account or workspace context.
3. Secrets and server-side controls
Sensitive provider credentials are kept in server-side configuration rather than exposed in public browser code. Server-side secret management is part of the documented security approach.
4. Abuse protection
Cloudflare Turnstile verification and rate limiting are used in relevant public-form flows. For contact-form rate limiting, the documented implementation uses a one-way secret-key-derived digest rather than retaining the raw IP for that purpose.
5. Google and Gmail permissions
Google Sign-In only handles basic identity for account sign-in. Gmail access is a separate optional connection and requires a separate user-granted permission.
6. Payments
Card payment details are handled by the payment provider used in the checkout flow and are not stored on Atlas Find servers.
7. Incident reporting
If you believe you found a security issue or account-compromise risk, email [email protected] with enough detail to reproduce or investigate it. Do not include unnecessary personal data or publicly disclose an active issue before we have a reasonable chance to review it.
8. Scope of this page
This page describes controls that are documented in the current product and public policies. It does not claim certifications or security guarantees that are not explicitly published by Atlas Find.
Use the email address associated with your account when relevant.
