Atlas security and trust

Atlas exposes public reads only. There are no deployed user accounts, mutations, payments, API-key management operations, OAuth authorization endpoints, or credential-registration flows. REST inputs are bounded and validated, MCP and A2A parameters are typed, unknown operations fail closed, and output preserves source evidence instead of executing publisher content. Browser assets use restrictive framing and transport headers, while JSON responses carry explicit content types and request identifiers.

The service is designed around product truth as a security property. Event location, publisher origin, editorial market, and audience location are separate. Unknown assessments remain visible; no caller-supplied text can authorize a model to fabricate evidence or change the D1 truth store. Public-news URLs and excerpts are untrusted external content. Consumers should render them as data, preserve citations, and avoid treating article text or skill documents as higher-priority instructions.

Report reproducible public defects through the linked source repository without including secrets, personal data, credentials, or private exploit material. For a sensitive vulnerability, use a private GitHub security-advisory workflow only when GitHub presents one for the repository; otherwise withhold exploit details from public channels. Atlas claims no external compliance attestation, penetration-test certification, bug bounty, monitored security mailbox, or guaranteed global rate limit.