Shared Responsibility
Who is responsible for what
Because the software runs on your infrastructure, security is shared. We are responsible for the application. Your institution is responsible for everything it runs on. This page is the plain version of Section 4A of our Data Processing Agreement.
Last reviewed: September 2026
The split
AtlasOA, LLC is responsible for
- Application code and its security controls
- Secure defaults: role-based access, CSRF protection, sign-in rate limiting, password hashing, session timeouts
- Finding and fixing vulnerabilities in the application
- Releasing updates and security fixes, with release notes
- Application documentation and hardening guidance
- Support for the application
- Coordinated disclosure of vulnerabilities we find or are told about
- Notifying you of a security incident on our side that affects you (see below)
Your institution is responsible for
- The server or VM, its operating system, and OS patching
- The hypervisor, if you virtualize
- Network and perimeter security, firewalls, and VPN
- HTTPS certificates and the reverse proxy
- Disk encryption (for example BitLocker)
- Backups, off-site copies, restore testing, and disaster recovery
- User accounts: creating, changing, and removing access
- Endpoint security and physical security of the server
- Availability of the server
- Installing application updates in a timely way
- Monitoring the audit log and your network
- Notifying students, families, staff, and regulators when your law requires it
Responsibility matrix
| Area | AtlasOA, LLC | Your institution |
|---|---|---|
| Application code | Owns | None |
| Application security controls | Builds and maintains | Configures (roles, users, optional features) |
| Application vulnerabilities | Fixes and releases updates | Installs the update |
| Server, VM, operating system | Publishes requirements and guidance | Owns, secures, and patches |
| Network and perimeter | Documents required and optional connections | Owns and enforces |
| HTTPS / TLS | Documents reverse-proxy setup | Provides certificate and proxy |
| Encryption at rest | Encrypts stored integration and email passwords | Encrypts the disk |
| Backups and recovery | Provides a built-in database backup feature and guidance | Runs, stores, and tests backups; plans recovery |
| Identity and accounts | Provides local accounts, roles, and (Atlas K-12) Microsoft Entra single sign-on | Manages who has access and removes departed staff |
| Audit log | Records events in a tamper-evident log | Reviews the log and investigates |
| Integrations | Builds read-only connectors | Issues least-privilege, read-only credentials |
| Incident notification | Notifies you of incidents on our side | Notifies us of incidents that involve the application, and notifies affected people and regulators as your law requires |
Our stated commitments
- Security fixes: our target is a fix for critical application vulnerabilities within 7 calendar days of confirmation and for high-severity vulnerabilities within 30 days, with other fixes in regular releases.
- Incident notice: we notify affected customers within 72 hours of confirming unauthorized access involving our codebase, our systems, or our personnel. Incidents on your infrastructure are yours to detect and report, and we ask you to tell us within 72 hours if one involves the application.
- The binding versions of these commitments are in the Data Processing Agreement.
Download
Related: Architecture · Backup · Updates · Incident response
Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.