Atlas Help · Gateway Home Platform

Security Overview

Version 1.9 · last revised 22 June 2026 · gw.atlas-help.online

1. Overview

This page describes the controls that protect Cloud Gateway on gw.atlas-help.online. It is a summary for administrators and prospective customers; the full control matrix and the most recent audit report are available under NDA.

2. Transport security

All endpoints require TLS 1.3. Older protocol versions, renegotiation and static RSA key exchange are disabled. HSTS is served with a one-year max-age, and certificates are issued from short-lived automation with certificate transparency monitoring on every domain.

3. Encryption at rest

Volumes and backups are encrypted with AES-256-GCM. Data-encryption keys are wrapped by a managed key service, rotated annually, and are never present in application configuration or in container images.

4. Access control

  • Administrative access requires hardware-backed multi-factor authentication.
  • Production access is time-boxed, approved per session, and recorded.
  • Engineers hold no standing credentials to customer data stores.
  • Role assignments are reviewed quarterly and on every role change.

5. Monitoring and audit

Authentication, authorisation and configuration events are written to an append-only log with a 90-day retention window and streamed to a separate account that operators cannot modify. Workspace administrators can export their own slice of the audit trail.

6. Change management

Every change is peer-reviewed, built reproducibly and deployed through staged rollout with automatic rollback on error-budget burn. Dependencies are scanned on each build; critical findings block the release pipeline.

7. Resilience

Backups run hourly with a 35-day rolling window and are restore-tested every month. The recovery objectives are four hours to restore service and one hour of maximum data loss; the last full exercise was completed in May 2026.

8. Incident response

A duty engineer is on call at all times. Confirmed incidents affecting customer data are reported to workspace administrators within 24 hours of confirmation, with a written post-incident review within ten business days.

9. Gateway isolation

Each workspace is served by its own policy set and connection table; no routing or session state is shared between workspaces. Region endpoints terminate TLS 1.3 only, reject renegotiation, and are rebuilt from an immutable image on every release.

🔒 Security contact: security@atlas-help.online. Encrypted reports are accepted; the current public key fingerprint is published in the workspace console.