The picture

AtlasOA and Atlas K-12 self-hosted architecture Inside the institution's network, staff browsers connect to a single Windows server running the application, its SQLite database, uploaded files, backups, and for Atlas K-12 the local Compass AI model. Optional connections the institution configures go to its own SIS or LMS, email relay, backup destination, Microsoft Entra for single sign-on, and public research websites. AtlasOA, LLC sits outside the network with no data connection to the server. YOUR INSTITUTION'S NETWORK (you control) Staff browsers Edge, Chrome, Firefox (Safari: Atlas K-12) HTTP(S) Your Windows server, VM, or PC Application (web app) runs as a tray app or Windows service Database one SQLite file Uploaded files evidence, report cards Backups database copies Compass AI model Atlas K-12 only, local Fetcher process (Atlas K-12) reaches only allowlisted research sites and your SIS No telemetry. No license server. No connection to AtlasOA, LLC. HTTPS through your reverse proxy (IIS or similar) Optional, you configure Your SIS or LMS (read only) Your email relay (alerts) Your backup destination Microsoft Entra ID (Atlas K-12 single sign-on, if enabled) Public research websites (Atlas K-12 strategy library, allowlisted, no student data) AtlasOA, LLC Website, installers, documentation, support email No data path to your server
Solid arrow: always present. Dashed arrow: only if your institution configures it. Staff browsers also load web fonts (and, in Atlas K-12, a charting library) from public content networks; see Network requirements.

Where your data lives

ItemAtlasOAAtlas K-12
ApplicationWindows desktop build under Program Files, or a Windows service installed from sourceWindows desktop build under Program Files
DatabaseOne SQLite file, database.db, in %LOCALAPPDATA%\AtlasOA for the installed buildOne SQLite file, atlas_k12.db, in %LOCALAPPDATA%\AtlasK12
Uploaded filesuploads\ beside the database (attachments, evidence portfolio)uploads\ beside the database (report cards, strategy resources)
Built-in backupsbackups_db\ beside the databasebackups\ beside the database
Audit logA separate hash-chained SQLite file, audit_log.db. In the installed build it currently sits in the application folder rather than the data folder; see Known limitations.A hash-chained table inside the main database
AI modelNone. AtlasOA has no AI model and makes no AI calls.A local model file loaded by the application on your server

All of these are ordinary files on your disk. Encryption at rest comes from your disk encryption (for example BitLocker); the applications do not encrypt the database themselves. Stored integration and email passwords are encrypted by the application. See Encryption.

Does AtlasOA, LLC keep a copy?

No. There is no AtlasOA cloud, no central student database, no telemetry, and no crash reporting. Neither application contacts us for licensing or updates. We only see institutional data if your staff choose to send it to us, for example by attaching a file to a support email. We ask you not to send student records; describe the problem or use sample data instead.

How the application runs

  • AtlasOA listens on port 5000 over plain HTTP on all network interfaces. The installer offers an optional Windows Firewall rule for that port, unchecked by default. With Windows Defender Firewall on and no other rule allowing it, the port is reachable only from the server itself; if Windows asks to allow network access on first run, decline unless you intend to expose it. For access across your network, put it behind a reverse proxy that provides HTTPS.
  • Atlas K-12 listens on 127.0.0.1:5050 by default (the server only). A network mode setting chooses between local only, your internal network over plain HTTP (with a startup warning), or behind a reverse proxy that provides HTTPS.
  • Neither application terminates HTTPS itself. HTTPS is provided by a reverse proxy such as IIS. See Network requirements.

What connects outward

With default settings, neither application sends institutional data anywhere. Optional features you configure connect to destinations you choose: your SIS or LMS, your email relay, your offsite backup location, and (Atlas K-12) Microsoft Entra ID for single sign-on and a short allowlist of public research websites used by the strategy library. Atlas K-12 enforces this in software: the main application refuses outbound connections, and research-site and SIS connections go only through a separate fetcher process restricted to an allowlist. The optional building health check runs as its own scheduled tool. The complete list is on Network requirements.

Who controls what

Your institution controls

  • The server, operating system, and network
  • Who can reach the application
  • The database, files, and backups
  • User accounts and roles
  • Which integrations are turned on
  • When updates are installed

AtlasOA, LLC controls

  • The application code and its security controls
  • Releasing updates and security fixes
  • Documentation and support
  • Nothing on your server: the software contains no remote-access capability for AtlasOA, LLC

The full split is on Shared responsibility.

How updates reach you

Updates are new installers that your IT staff download and run when they choose. Neither product updates itself or checks for updates. See Updates and patching.

Supported deployment shapes

  • Internal network only, with VPN for off-site staff.
  • A public address behind your reverse proxy with HTTPS (Atlas K-12 adds Microsoft Entra single sign-on for this shape).
  • Atlas K-12 also documents site-to-site VPN and fully air-gapped installations.
  • Not supported: hosted SaaS, Docker or Kubernetes, Linux or macOS servers, and one installation shared by several institutions.

Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.