What has been independently validated, and what has not
Institutions should be able to tell the difference between what a vendor says, what the architecture guarantees, what has been tested internally, and what an independent party has verified. Here is exactly where AtlasOA and Atlas K-12 stand.
Last reviewed: September 2026
Current status
| Validation | Status | Date | Notes |
|---|---|---|---|
| Third-party penetration test | Not yet completed | None | No independent firm has tested either product. When one does, the assessor, scope, date, and a summary of results will be listed here. |
| Anthropic Cyber Verification Program | Enrolled, active | September 2026 | Our development organization is verified under Anthropic's program for defensive cybersecurity work. It lets our team use Claude, including the Fable model, for deeper AI-assisted security testing of both products on isolated test systems with synthetic data. Testing is under way; a results summary will be added here. This is AI-assisted internal testing, not a third-party penetration test or certification, and Anthropic does not endorse or certify our products. |
| SOC 2 Type I or Type II | No | None | AtlasOA, LLC does not operate a hosted service, which is what SOC 2 usually examines. We do not hold a SOC 2 report. |
| ISO/IEC 27001 | No | None | |
| HECVAT or other standard security questionnaire | Not yet published | None | We have not published a completed HECVAT. Ask us about your institution's questionnaire. |
| Accessibility conformance report (VPAT) | Not yet completed | None | See Accessibility. |
| FERPA or COPPA certification | Not applicable | No government certification exists for software under FERPA or COPPA. See Privacy for how the products support your obligations. | |
| Code signing of installers | Not yet | Installers are not code-signed yet. AtlasOA evaluation installers come with a SHA-256 hash to verify. | |
| Internal security reviews | Ongoing | Atlas K-12 platform review June 2026; AtlasOA release review 2026-09-14 | Internal reviews with separate verifiers. Atlas K-12: 43 findings, all closed. Summaries are in the changelog. |
| Automated security tests | In place | Run before recent releases | See How we build and test. |
Six kinds of evidence
We encourage reviewers to weigh these separately, for us and for any vendor:
- Vendor statements. What we say, including this site. Useful, but only as good as our honesty.
- Architecture. Facts that follow from how the software is built. For example, because the database lives on your server, we cannot lose it in a breach of our systems. You can verify this yourself.
- Implemented controls. Features you can see and test in the software: roles, audit logs, rate limiting, and the rest on Security.
- Internal testing. Our automated tests and internal reviews. We have these.
- Independent third-party testing. A penetration test by an outside firm. We do not have this yet.
- Formal attestations. SOC 2, ISO 27001, and similar. We do not have these.
Validate it yourself
Because the software runs on your infrastructure, your security team can examine it directly during a 30-day evaluation: scan it, monitor its network traffic, test its access controls, and inspect its database and files. Please tell us what you find through vulnerability reporting. We would rather hear it from you than from anyone else.
When this page changes
When an independent assessment is completed, its row above will show the assessor, the date, the scope, and a summary, and a copy of the summary report will be available to institutions under a non-disclosure agreement. Until then, the honest answer is: not yet.
Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.