1. Security Objective
Atlas maintains a security program designed to protect the confidentiality, integrity, and availability of customer information and platform systems in light of the nature of the Services and reasonably foreseeable threats. Security is a shared responsibility, and no online system can be guaranteed immune from compromise, interruption, or data loss.
2. Access Controls
Atlas uses access controls designed to limit systems and information to authorized personnel and services. Depending on the system and risk, controls can include authentication, multi-factor authentication, role-based or least-privilege access, secrets management, logging, and periodic access review. Controls can evolve as systems and risks change.
3. Encryption and Secure Communications
Atlas uses industry-standard cryptographic protections where appropriate for data in transit and sensitive data at rest. Specific protocols, algorithms, and provider implementations may change as standards and systems evolve. Encryption reduces risk but does not guarantee that information or systems cannot be compromised.
4. Brokerage Credentials and Tokens
Atlas is designed to use brokerage-approved connection methods. OAuth or similar token-based connections can reduce the need for Atlas to receive a user's brokerage password. Some integrations may use API keys or other delegated credentials. Tokens and keys remain sensitive credentials and are protected through access and security controls appropriate to their use.
Atlas uses brokerage permissions for enabled connected-platform functionality, including authorized order generation, transmission, modification, and cancellation, account display, and reconciliation. Atlas does not obtain authority to withdraw or transfer customer brokerage assets.
5. Monitoring, Vulnerability Management, and Incident Response
Atlas maintains processes intended to detect, investigate, contain, and respond to security events and vulnerabilities. These processes may include internal or third-party scanning, logging, alerts, testing, investigation, remediation, and recovery practices. No monitoring or testing program can identify or prevent every issue.
6. Third-Party Risk
Atlas relies on cloud providers, broker APIs, payment processors, communications providers, market-data providers, and other service providers. Atlas uses vendor diligence and contractual or security controls appropriate to the service, but cannot guarantee that a third party will never experience an incident or outage.
7. Secure Development and Change Management
Atlas maintains development and change-management practices appropriate to the platform, which can include code review, testing, controlled access, separation of environments where practical, monitored deployment, rollback planning, and incident procedures. Security controls are adjusted based on the systems, feature, and risk.
8. Customer Security Responsibilities
You must use unique credentials; protect your devices, email account, and authentication methods; enable available multi-factor authentication; review Atlas and brokerage activity; avoid sharing credentials; keep contact information current; and notify Atlas and the brokerage promptly of suspected unauthorized access.
Atlas will not ask you to provide a brokerage password, one-time authentication code, or full payment-card number through an ordinary support message. Do not send those items in a support ticket or email. Atlas cannot protect against every consequence of a compromised customer device, email account, brokerage account, or authentication method.
9. Security Incidents and Notices
If Atlas determines that a security incident triggers a legal notification obligation, Atlas will provide notices as required by applicable law. Atlas may also take protective actions such as resetting sessions, disabling connections, pausing affected functionality, or requiring re-authentication.
10. Responsible Disclosure
Good-faith reports of suspected vulnerabilities may be sent to [email protected] with "Security Report" in the subject line. Do not access customer data, disrupt production trading, perform denial-of-service testing, use social engineering, or test third-party brokerage systems without written authorization. Atlas may request sufficient information to investigate and may coordinate remediation and disclosure timing.