Current status

Applies to both AtlasOA and Atlas K-12 unless noted. Last reviewed September 2026.
ValidationStatusDateNotes
Third-party penetration testNot yet completedNoneNo independent firm has tested either product. When one does, the assessor, scope, date, and a summary of results will be listed here.
Anthropic Cyber Verification ProgramEnrolled, activeSeptember 2026Our development organization is verified under Anthropic's program for defensive cybersecurity work. It lets our team use Claude, including the Fable model, for deeper AI-assisted security testing of both products on isolated test systems with synthetic data. Testing is under way; a results summary will be added here. This is AI-assisted internal testing, not a third-party penetration test or certification, and Anthropic does not endorse or certify our products.
SOC 2 Type I or Type IINoNoneAtlasOA, LLC does not operate a hosted service, which is what SOC 2 usually examines. We do not hold a SOC 2 report.
ISO/IEC 27001NoNone
HECVAT or other standard security questionnaireNot yet publishedNoneWe have not published a completed HECVAT. Ask us about your institution's questionnaire.
Accessibility conformance report (VPAT)Not yet completedNoneSee Accessibility.
FERPA or COPPA certificationNot applicableNo government certification exists for software under FERPA or COPPA. See Privacy for how the products support your obligations.
Code signing of installersNot yetInstallers are not code-signed yet. AtlasOA evaluation installers come with a SHA-256 hash to verify.
Internal security reviewsOngoingAtlas K-12 platform review June 2026; AtlasOA release review 2026-09-14Internal reviews with separate verifiers. Atlas K-12: 43 findings, all closed. Summaries are in the changelog.
Automated security testsIn placeRun before recent releasesSee How we build and test.

Six kinds of evidence

We encourage reviewers to weigh these separately, for us and for any vendor:

  1. Vendor statements. What we say, including this site. Useful, but only as good as our honesty.
  2. Architecture. Facts that follow from how the software is built. For example, because the database lives on your server, we cannot lose it in a breach of our systems. You can verify this yourself.
  3. Implemented controls. Features you can see and test in the software: roles, audit logs, rate limiting, and the rest on Security.
  4. Internal testing. Our automated tests and internal reviews. We have these.
  5. Independent third-party testing. A penetration test by an outside firm. We do not have this yet.
  6. Formal attestations. SOC 2, ISO 27001, and similar. We do not have these.

Validate it yourself

Because the software runs on your infrastructure, your security team can examine it directly during a 30-day evaluation: scan it, monitor its network traffic, test its access controls, and inspect its database and files. Please tell us what you find through vulnerability reporting. We would rather hear it from you than from anyone else.

When this page changes

When an independent assessment is completed, its row above will show the assessor, the date, the scope, and a summary, and a copy of the summary report will be available to institutions under a non-disclosure agreement. Until then, the honest answer is: not yet.

Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.