Trust & Security

Security at Atlas.

How we protect your account, your payments, and your data — explained plainly, with no claims we can't back up.

Payments

Secure Payments

Our own gateway, acquiring banks, and an isolated card vault.

Card data is locked down

Payments run through a dedicated payment gateway and a merchant account with our acquiring banks. Your card details are confined to an isolated, encrypted card-data environment — engineered to the PCI DSS SAQ D standard with dedicated key management, and walled off from the main Atlas application and database.

Verified by signature

Payment and billing events from our gateway are cryptographically signature-verified before we act on them, with idempotency so a replayed event can't double-charge.

Payouts by bank transfer

Creator earnings are paid out through a dedicated payout provider over bank transfer (ACH); creators' bank details are encrypted at rest and never shown in full.

On iOS, Apple handles it

In-app purchases on iPhone and iPad are processed by Apple through the App Store — card data there never reaches Atlas.

Where we stand on PCI DSS

Atlas processes payments through a dedicated payment gateway and a merchant account with our acquiring banks. Card data is confined to an isolated environment validated to PCI DSS SAQ D — the most rigorous self-assessment tier — with dedicated key management (AES-256-GCM via a managed KMS), walled off from the main application and database.

Validated
Accounts

Account Security

Layered protection on every sign-in.

Only you get in

Sign-in is defended in depth: passwords are salted and one-way hashed, repeated failures lock the account, auth endpoints are rate-limited, and we email you the moment your account is accessed — with the IP and device.

Two-factor authentication

Add a second factor — a one-time code on top of your password — so a leaked password alone can't get into your account.

Brute-force defense

Repeated failed attempts temporarily lock the account, and auth endpoints are rate-limited per IP through our trusted edge proxy.

Verified identity

Email is confirmed with a time-limited, hashed one-time code, compared in a timing-safe way. Optional one-time SMS verification for phone signups.

Sign in with Google

OAuth 2.0 sign-in backed by server-side anti-CSRF state validation and open-redirect protection.

Safer sessions

Session cookies are HttpOnly with SameSite and Secure (HTTPS-only) flags in production. Resets are single-use and expire in 15 minutes; logging out clears your session.

No info leaks

Sign-in and password-reset responses are uniform, so they never reveal whether an email is registered.

5 → 30 minlockout after failed sign-ins Five failed attempts temporarily locks the account for 30 minutes.
SHA-256one-time codes hashed Email and password-reset codes are hashed and compared in a timing-safe way.
Messaging

Secure Messaging

Authenticated, encrypted, and yours to control.

Encrypted messages

Direct messages are encrypted — each one is sealed with your account's key and stored as ciphertext, never plain text. Because Atlas manages your keys (so your messages follow you across devices and can be recovered if you lose one), our systems can technically access message content — and we'd rather say that plainly than imply more. Messages are authenticated, and mutual blocking still applies.

Blocking is mutual

Block someone and they can't message, follow, comment on, or like you — enforced across feeds, search, conversations, and profiles, not just cosmetically.

Report for review

You can report messages and videos. Reports go to an admin moderation queue and are reviewed by our team.

Delete your messages

Delete messages you've sent — only the sender can remove their own message, and the content is replaced with a placeholder.

wss:// · TLSencrypted real-time delivery Direct messages are delivered over an authenticated, TLS-encrypted WebSocket.
Two-waymutual blocking Blocking applies in both directions across feeds, search, conversations, and profiles.
Data

Data Encryption

Encrypted in transit, and at rest where it counts.

Bank details masked

Creator routing and account numbers are encrypted at rest, and only the last four digits are ever displayed back — never the full number.

Secrets out of code

API keys and signing secrets are loaded from environment configuration and are never committed to source control.

Managed database

Our database runs on Render's managed PostgreSQL, which encrypts stored data at rest at the infrastructure level.

TLS · HSTSencrypted in transit HTTPS everywhere, with a one-year HSTS policy in production so browsers refuse plain HTTP.
AES-128+ HMAC-SHA256 · Fernet Authenticated encryption at rest for connected-account tokens and creator bank details.
CSP · nosniffsecurity headers Content-Security-Policy, X-Frame-Options, nosniff, and Referrer-Policy on every response.
Privacy

Your Privacy

Clear rights, real controls, no trackers.

Your privacy rights

Our Privacy Policy covers your GDPR and CCPA rights — access, erasure, and portability — with stated retention periods.

Essential cookies only

We show a cookie notice and use only essential cookies. There are no third-party advertising or analytics trackers in the product.

Email you control

Every email includes a one-click unsubscribe, and you can turn off message-notification emails in your settings.

Connected accounts stay in your control

When you link a third-party account (like Telegram, X, or TikTok), we store its login encrypted and use it only for the features you turn on. Some connections, such as Telegram, use account-level access; we never sell or share it, and disconnecting deletes the stored credentials. See our Privacy Policy.

GDPR · CCPArights honored Access, erasure, and portability, with stated retention periods in our Privacy Policy.
0third-party trackers No third-party advertising or analytics trackers in the product — essential cookies only.
Safety

Trust & Safety

Clear rules, real enforcement, built-in defenses.

Reported, reviewed, removed

Adult/NSFW and other prohibited content is banned by our Community Guidelines and removed through reporting and human moderator review. See our Content Moderation policy.

Input validated & sanitized

User input such as emails, usernames, and bios is validated and sanitized, and template output is escaped to guard against injection attacks.

Copyright protection

Rights holders can submit takedowns through our DMCA policy.

Humanreviewed reports Reports go to an admin moderation queue and are reviewed by our team.
DMCAtakedown process Rights holders can submit copyright takedowns and we act on valid notices.

Built to be trusted.

Create an account and see it for yourself — or read the policies that back all of this up.

Get Started