Atlas
Sign in

Atlas ยท Product information

Security

Report a suspected vulnerability, environment escape, exposed token or cross-account issue privately to our security contact.

How to report

Email martin@shinrasec.com with the affected surface, time observed, impact and reproducible steps. Do not include live credentials in the first message; we will provide a secure transfer method when needed.

Research boundaries

Do not access other customers' data, disrupt the service, or publish sensitive details before we have had a chance to investigate. Testing confined to your own account and the material you submit is welcome.

What to expect

We aim to acknowledge credible private-beta security reports within two business days, coordinate validation and remediation, and keep reporters informed. This is a response target rather than a contractual service level unless your agreement says otherwise.

Operational security

Atlas authenticates every account through Shinra ID, isolates accounts, runs chat execution in a disposable environment with public-only egress and no route to the host or private networks, delivers scoped API credentials that can be revoked individually, and stores only content-free usage records for its outcome measurement. Detailed architecture or assurance material may be shared with customers under appropriate confidentiality terms.

Effective 2026-08-07 · Shinrasec, operated by Martin Mielke