Every connection, and why it exists
Neither product needs internet access for normal operation. There are no telemetry, licensing, update-check, or AI endpoints to allow. Everything outbound below is optional and exists only if you turn on the feature that uses it.
Last reviewed: September 2026
Endpoints that do not exist
- No telemetry, analytics, or crash reporting
- No license server: AtlasOA keys are verified locally; Atlas K-12 has no license check
- No update server or update check
- No hosted AI service (OpenAI, Anthropic, Google, or any other)
- No connection to AtlasOA, LLC
Inbound
| Product | Default | Network access |
|---|---|---|
| AtlasOA | HTTP on TCP 5000, listening on all interfaces. The installer offers a Windows Firewall rule for port 5000, unchecked by default. | Recommended: keep 5000 closed to the network and publish the application through a reverse proxy on TCP 443 (HTTPS) with your certificate. |
| Atlas K-12 | HTTP on TCP 5050, listening on the server only (127.0.0.1). | Choose a network mode: local only; your internal network over plain HTTP (a startup warning appears); or behind a reverse proxy on TCP 443 (HTTPS), which also turns on secure cookies and HSTS. |
Restrict inbound access to your staff networks and VPN. Neither product has a built-in IP allowlist; use your firewall or reverse proxy.
Outbound (all optional)
| Purpose | Product | Destination | Port / protocol | What is sent |
|---|---|---|---|---|
| Jenzabar J1 / EX sync | AtlasOA | Your SQL Server | TCP 1433 (or your port), encrypted | Read-only queries |
| LMS sync (Canvas, Blackboard, Moodle, Jenzabar CX) | AtlasOA | Your LMS or API address | TCP 443, HTTPS | An API token (Canvas, Moodle) or client credentials to obtain a token (Blackboard, Jenzabar CX), then read requests. Moodle sends its token in the request address. |
| SIS sync (API connectors, OneRoster, Ed-Fi) | Atlas K-12 (fetcher process) | Your SIS address, as configured | TCP 443, HTTPS | An API key (Aeries, Synergy) or client credentials to obtain a token (others), then read requests |
| SFTP file intake | Atlas K-12 (fetcher process) | Your SFTP server | TCP 22 | Login, then file downloads; unknown host keys are rejected |
| Email alerts | Both | Your SMTP server or relay | TCP 587 (STARTTLS) or 465 (AtlasOA) | Alert messages. AtlasOA alerts contain course and outcome summaries, not student names. Atlas K-12 tier-change alerts contain the student's name, grade, area, and old and new tier. Atlas K-12's outbound guard may require a relay on the server itself; confirm during evaluation. |
| Offsite backup | AtlasOA | Your network share, SFTP server, or S3-compatible storage | SMB, TCP 22, or TCP 443 | Backup files |
| Single sign-on | Atlas K-12 | login.microsoftonline.com | TCP 443, HTTPS | Standard OpenID Connect sign-in exchange and Microsoft's public signing keys. Allowed only while single sign-on is enabled and fully configured. |
| Strategy library link checks and caching | Atlas K-12 (fetcher process) | An allowlist of 8 public research organizations: IRIS Center (Vanderbilt), IES What Works Clearinghouse, PBIS World, CASEL, Attendance Works, Intervention Central, Reading Rockets, and Understood.org | TCP 443, HTTPS | Page addresses and a user agent; never student data. Administrators can turn sources off. |
| Building health check | Atlas K-12 (separate scheduled tool) | Each school's status page address, if you configure one | HTTP(S) | A status request |
With every optional feature off, both products work with all outbound traffic blocked. Atlas K-12 also enforces this in software: its main application refuses non-local connections and logs each attempt.
At startup, AtlasOA learns its own network address by opening a UDP socket toward 8.8.8.8. No packet is sent; it only reads which local interface would be used. Some monitoring tools may still show the lookup.
Requests made by staff browsers
These come from staff computers, not the server, when someone opens the application:
fonts.googleapis.comandfonts.gstatic.com: the Inter typeface (both products).cdn.jsdelivr.net: the Chart.js charting library (Atlas K-12).
They carry the browser's IP address and user agent, and no application data. If you block them, pages use system fonts, and Atlas K-12 charts may not display. See Subprocessors.
DNS
- Create an internal DNS name for the server (for example
atlas.yourdistrict.local) and point your reverse proxy certificate at it. - External DNS is needed only for the optional outbound features above.
Air-gapped installations
Atlas K-12 supports fully air-gapped sites: bring the installer and model files in on removable media. In that configuration, SIS API sync, single sign-on, the strategy library's link checks, and browser font and chart downloads are unavailable. Use CSV imports and local accounts.
Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.