Atlas ยท Product information
Security
Report a suspected vulnerability, environment escape, exposed token or cross-account issue privately to our security contact.
How to report
Email martin@shinrasec.com with the affected surface, time observed, impact and reproducible steps. Do not include live credentials in the first message; we will provide a secure transfer method when needed.
Research boundaries
Do not access other customers' data, disrupt the service, or publish sensitive details before we have had a chance to investigate. Testing confined to your own account and the material you submit is welcome.
What to expect
We aim to acknowledge credible private-beta security reports within two business days, coordinate validation and remediation, and keep reporters informed. This is a response target rather than a contractual service level unless your agreement says otherwise.
Operational security
Atlas authenticates every account through Shinra ID, isolates accounts, runs chat execution in a disposable environment with public-only egress and no route to the host or private networks, delivers scoped API credentials that can be revoked individually, and stores only content-free usage records for its outcome measurement. Detailed architecture or assurance material may be shared with customers under appropriate confidentiality terms.