← Back to VEV

Security & trust

Trust CenterHow we protect your map.

Atlas gives you one living view of your entire IT landscape. That same view would be gold to an attacker. This page describes exactly how we protect it — and how you decide how far your data reaches at all. We believe in evidence over promises.

Data residency

You choose where your data lives.

The map is only ever assembled in one place if you decide it should be. Pick the deployment model that matches how far your data is allowed to travel.

Model Best for Where your data lives
Self-hosted (Community) Sovereignty-conscious organisations 100% with you. One docker compose up, no call home to us.
VEV-hosted (EU) Customers who want operations taken off their hands With us, EU-resident. You own your data; we run the platform.
Air-gapped Regulated environments and public sector Fully offline, signed licence with no live calls to our control plane.

Whatever the model — open contracts and full export mean you can always take your map with you.

Protection

How we protect the map.

A map of your architecture is a high-value target. The design choices below exist to keep it useful to you and useless to anyone else.

  • Strict tenant isolation.

    All data is separated per organisation at the source — every request is bound to your tenant. The isolation sits in several layers, so a single slip in the code cannot leak across tenants.

  • Encryption.On the way

    Data is encrypted in transit today. On the way: in our hosted environment it will also be encrypted at rest, with the most sensitive fields protected separately. For self-hosted installations we document how you encrypt your own storage.

  • Least data.

    A map should describe your architecture — not store your secrets. We deliberately design to keep as little sensitive detail as possible.

  • Immutable audit log.

    Changes and exports are recorded in an append-only audit log you can read yourself. A full export of your landscape can never happen silently.

  • Fail-static by default.

    If something fails, we close down rather than open up. Access is decided by an offline evaluator that denies on doubt — never grants on error.

Open core

Open core — security you can audit.

Atlas Community is open source under AGPL-3.0: your security team can read the code that receives, stores and separates your data — before you install. The data model and import/export formats are published as open contracts (Apache-2.0). That is what makes portability real, not a promise.

AI

On the way

AI with control, not AI at any price.

Atlas' AI features are optional and pass through a governed gateway. The guarantees below describe how they are being built; we will state them in the present tense only once they are confirmed live.

  • No training on your data.

    When enabled, landscape data will not be used to train third-party models.

  • EU-resident inference.

    When enabled, inference is kept EU-resident.

  • Sensitive content filtered.

    When enabled, sensitive content is filtered before it reaches a model.

Compliance

Compliance & regulatory stance.

We build Atlas in line with GDPR, DORA, NIS2 and the EU Cyber Resilience Act, and attach signed provenance and an SBOM to our software.

Certifications: we are working toward formal certifications; this page is updated as they land — we never list a certificate we don't hold.

For your security team

Marketing doesn't convince a CISO — evidence does.

The security whitepaper is available to download now. The deeper items are provided on request — contact us and we'll tell you exactly what's ready and a timeline for the rest.

  • Security whitepaper and architecture / data-flow diagrams
  • Threat models
  • SBOM and signed provenance
  • Penetration-test summary (on the way)
  • Completed security questionnaire (CAIQ/SIG), DPA and subprocessor list (on the way)

Responsible disclosure

Report a vulnerability.

Report privately — not in a public issue. We coordinate the fix and disclosure case by case, and we credit reporters who want it.