The split

AtlasOA, LLC is responsible for

  • Application code and its security controls
  • Secure defaults: role-based access, CSRF protection, sign-in rate limiting, password hashing, session timeouts
  • Finding and fixing vulnerabilities in the application
  • Releasing updates and security fixes, with release notes
  • Application documentation and hardening guidance
  • Support for the application
  • Coordinated disclosure of vulnerabilities we find or are told about
  • Notifying you of a security incident on our side that affects you (see below)

Your institution is responsible for

  • The server or VM, its operating system, and OS patching
  • The hypervisor, if you virtualize
  • Network and perimeter security, firewalls, and VPN
  • HTTPS certificates and the reverse proxy
  • Disk encryption (for example BitLocker)
  • Backups, off-site copies, restore testing, and disaster recovery
  • User accounts: creating, changing, and removing access
  • Endpoint security and physical security of the server
  • Availability of the server
  • Installing application updates in a timely way
  • Monitoring the audit log and your network
  • Notifying students, families, staff, and regulators when your law requires it

Responsibility matrix

AreaAtlasOA, LLCYour institution
Application codeOwnsNone
Application security controlsBuilds and maintainsConfigures (roles, users, optional features)
Application vulnerabilitiesFixes and releases updatesInstalls the update
Server, VM, operating systemPublishes requirements and guidanceOwns, secures, and patches
Network and perimeterDocuments required and optional connectionsOwns and enforces
HTTPS / TLSDocuments reverse-proxy setupProvides certificate and proxy
Encryption at restEncrypts stored integration and email passwordsEncrypts the disk
Backups and recoveryProvides a built-in database backup feature and guidanceRuns, stores, and tests backups; plans recovery
Identity and accountsProvides local accounts, roles, and (Atlas K-12) Microsoft Entra single sign-onManages who has access and removes departed staff
Audit logRecords events in a tamper-evident logReviews the log and investigates
IntegrationsBuilds read-only connectorsIssues least-privilege, read-only credentials
Incident notificationNotifies you of incidents on our sideNotifies us of incidents that involve the application, and notifies affected people and regulators as your law requires

Our stated commitments

  • Security fixes: our target is a fix for critical application vulnerabilities within 7 calendar days of confirmation and for high-severity vulnerabilities within 30 days, with other fixes in regular releases.
  • Incident notice: we notify affected customers within 72 hours of confirming unauthorized access involving our codebase, our systems, or our personnel. Incidents on your infrastructure are yours to detect and report, and we ask you to tell us within 72 hours if one involves the application.
  • The binding versions of these commitments are in the Data Processing Agreement.

Download

Related: Architecture · Backup · Updates · Incident response

Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.