Security

Built with security at the foundation

Inspection data is sensitive. Here's how Atlas Inspections protects your buildings, images, and client information.

Core practices

How we protect your data

Transport & storage review

We confirm current transport, storage, and key-management details during a security review rather than publishing blanket algorithm or version claims that may become stale.

Managed deployment

Atlas is deployed on Replit's managed infrastructure. Confirm current hosting, data-location, and subprocessor details with us for your procurement requirements.

Managed authentication

Sign-in is handled by a managed authentication provider. Available sign-in methods and organization-specific identity requirements should be confirmed during evaluation.

Scoped Gmail access

When you connect Gmail, we request only the gmail.send scope. The integration's stored refresh tokens are encrypted with AES-256-GCM, and the application does not return those tokens in API responses.

Access controls

Application roles and tenant checks restrict protected routes and records. Access varies by role and assignment; request a role-and-permission walkthrough if this is material to your review.

Audit logging

Atlas records defined administrative and security-relevant actions with actor and time information. Ask us for the current event inventory and retention details rather than assuming every action is captured.

Procurement

What to confirm in a security review

This page describes controls visible in the current product and repository. It is not a certification, audit report, or service-level commitment.

Identity & access

Atlas has managed sign-in, application roles, tenant isolation checks, and administrative access controls. Contact us to validate your required identity-provider and sign-in configuration.

Data handling

Ask for current answers on hosting location, subprocessors, retention, deletion, encryption boundaries, and key management; do not infer them from a plan name.

Operations & resilience

Recovery objectives, backup practices, incident-response commitments, support response times, and availability terms are confirmed in writing when applicable.

Assurance evidence

Request the current security questionnaire response and any evidence available for your review. No independent audit, testing cadence, or certification is represented on this page.

Vulnerability disclosure

Found a security issue?

We take security reports seriously and will work to address confirmed vulnerabilities promptly.

If you've discovered a potential security vulnerability in Atlas Inspections, please report it to us via the link below or the contact form before disclosing it publicly. The listed Gmail address is our current public inbox; an owned-domain security address is not documented in this repository. We ask that you:

  • Describe the vulnerability and the steps needed to reproduce it.
  • Include any proof-of-concept if available.
  • Give us reasonable time to investigate and remediate before disclosure.
  • Do not access, modify, or exfiltrate user data beyond what is needed to demonstrate the issue.
Report a vulnerability

Questions about security?

We're happy to discuss our practices in more detail for enterprise evaluations or compliance reviews.