How your data is protected
Atlas follows industry standards for storing and transmitting financial data — and describes here what is actually in place, nothing more.
- Encrypted connection between your browser and our servers (TLS), and between our servers and the database.
- Data encrypted at rest by our database provider.
- No password to steal: sign-in by one-time code, signed link or Google, with rate-limited attempts.
- Auto-expiring sessions, secure cookies (HttpOnly, Secure), account isolation checked server-side on every request.
What Atlas never does
Our business model relies on subscriptions (free during the beta), not on your data.
- Your data is never sold.
- Never shared with advertisers or data brokers.
- Never used to train AI models — the copilot queries Anthropic under a contract that excludes training, and only with your express consent.
- No advertising in Atlas, and no targeting based on your activity.
- No commercial partnership around your financial activity.
Your controls
You can export, modify or delete your data from your account at any time — without asking our permission.
- Full export of your wealth as JSON (structured), CSV or PDF (readable).
- Self-service permanent account deletion: your data is erased immediately; only a minimal security log is kept for 12 months, then purged automatically.
- Free modification and correction at any time.
- Consent withdrawal (AI copilot, news emails) directly in your profile.
Hosting and jurisdiction
Atlas is operated from Québec; the infrastructure relies on specialized providers, mainly in the United States — and we tell you which ones.
- Team and operations: Québec, Canada.
- Database: Neon (United States). Application: Cloudflare (global network). Email: Resend (US). AI copilot: Anthropic (US, only with your express consent).
- Every communication outside Québec was assessed under Law 25, with contractual data-protection commitments.
- The complete list and details are in the privacy policy (section 6).
Audits and compliance
We publish the real state of things, without embellishment.
- No certification published to date (the app is in beta) — we will only announce an audit once it is under way.
- Good-faith vulnerability reports are welcome and treated confidentially (security@atlasfinance.app).
- In place today: admin access logging, automatic retention purge, confidentiality incident register.
- This page is updated with every significant change.
Report a security issue
If you find a vulnerability, contact us directly. We respond within 72 hours and we treat reports in confidence.