1. Our Commitment to Security
RED Atlas maintains administrative, technical, and physical safeguards designed to protect the RED Atlas platform and the data it holds, including encryption of data in transit, role-based access controls, network and application monitoring, logical separation of customer data, and regular review and testing of our security practices. Our services are hosted in secure, access-controlled data centers operated by leading cloud infrastructure providers. No security program can guarantee perfect security; this page explains how to reach us if you find a problem.
2. Reporting a Vulnerability
If you believe you have found a security vulnerability in any RED Atlas system — atlas.red, app.atlas.red, the RED Atlas API, our AI Connectors, or our mobile applications — please report it to security@atlas.red with: a description of the issue and its potential impact; steps to reproduce it (proof-of-concept); and the URL, endpoint, or component affected. We also publish this contact at atlas.red/.well-known/security.txt. We will acknowledge your report within three (3) business days, keep you informed as we investigate, and tell you when the issue is resolved.
3. Rules for Good-Faith Research
To protect our users and their data, when researching you must: access only your own accounts and data, and stop and report immediately if you encounter anyone else's data; avoid degrading the Service (no denial-of-service, resource exhaustion, or spam); never use social engineering, phishing, or physical intrusion; not publicly disclose an issue until we have confirmed a fix or ninety (90) days have passed since your report, whichever comes first; and not demand payment as a condition of disclosure. Automated scanning must respect rate limits.
4. Safe Harbor
RED Atlas will not initiate legal action — including under the Computer Fraud and Abuse Act, the Digital Millennium Copyright Act's anti-circumvention provisions, or our Terms of Service — against security research conducted in good faith and in compliance with this policy, and we will consider such research authorized. This safe harbor does not apply to research that violates this policy, harms users or data, or breaks the law independent of the access itself; and it cannot bind third parties.
5. Scope and Recognition
Out of scope: findings requiring physical access or stolen credentials; vulnerabilities in third-party services we do not operate (report those to the vendor); clickjacking on pages with no sensitive actions; missing best-practice headers without demonstrated impact; and reports from automated tools without a working proof of concept. RED Atlas does not currently operate a paid bug-bounty program; with your permission, we are glad to credit meaningful findings on this page.
6. Customer Security Questions
Enterprise customers with security questionnaires, audit-report requests, or incident-notification questions should contact their account manager or security@atlas.red. Data-protection commitments for Enterprise customers are set out in the Data Processing Addendum.