Security Policy
Last updated: August 2, 2026
At Atlas, we take the security of your data seriously. This page summarizes the technical and organizational measures we use to protect your information.
1. Encryption
- In transit: All traffic to and from atlasgrowth.app is encrypted using TLS (HTTPS). No data is transmitted over unencrypted connections.
- At rest: Data stored in our database (Supabase, PostgreSQL) is encrypted at rest using industry-standard encryption provided by our infrastructure provider.
2. Access Control
- Access to your account requires authentication via Supabase Auth (email/password or supported providers).
- Row Level Security (RLS) is enforced at the database level — each user's data (billing records, consent logs, connected shop data) is scoped so that only that user (or our service-level backend where strictly necessary) can access it.
- Administrative access to production systems (Vercel, Supabase, Paddle) is limited to the founder/operator and protected by unique credentials; we do not share shared/generic logins.
- We recommend you enable strong, unique passwords for your Atlas account.
3. Infrastructure and Data Location
- Application hosting: Vercel (global edge network).
- Database and authentication: Supabase, hosted in Frankfurt, Germany (EU region — eu-central-1).
- AI-powered features (Atlas Coach, Atlas Studio): processed via Anthropic's API (United States); no Etsy shop data is used to train third-party AI models.
- Payment processing: Paddle.com Market Limited, acting as Merchant of Record — we do not store your full payment card details on our own systems.
4. Vendor Security
We select infrastructure providers (Supabase, Vercel, Paddle, Anthropic) based on their published security and compliance practices, and we limit the data shared with each provider to what is necessary for them to perform their function. See our Privacy Policy for the full list of subprocessors.
5. Backups and Availability
Our database provider (Supabase) performs automated backups of production data. In the event of an infrastructure failure, we work with our providers to restore service as quickly as possible.
6. Monitoring and Incident Response
We monitor our production systems for errors and anomalies. In the event of a suspected data security incident, we follow our internal incident response procedure, which includes assessing the scope of the incident, notifying affected users and, where legally required, the relevant regulatory authorities (including under GDPR's 72-hour rule and KVKK's requirements) within the applicable timeframes.
7. Reporting a Security Issue
If you believe you've found a security vulnerability in Atlas, please report it to us directly at support@atlasgrowth.app rather than disclosing it publicly. We appreciate responsible disclosure and will respond as quickly as we can.
8. Changes to This Policy
We may update this policy as our security practices evolve. Material changes will be reflected here with an updated “Last updated” date.