AtlasWork, planned itself.

The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

  • SOC 2 II
  • ISO 27001
  • HIPAA
  • GDPR

Product

  • Overview
  • PDF tools
  • People & HR
  • Integrations
  • Marketplace
  • Pricing

Resources

  • Guides
  • Docs
  • API reference
  • Support
  • Changelog
  • Status

Company

  • About
  • Careers
  • Press
  • Contact

Legal & trust

  • Trust center
  • Security
  • Privacy
  • Terms
  • DPA
  • GDPR
  • SLA
  • Refunds
Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
Made in India
Skip to content
Atlas Task ManagerLegal
  • Home
  • Sign in

Policies

  • Overview
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use Policy
  • Security & Disclosure
  • Sub-processors
  • Google API Disclosure
  • DMCA Policy

Security & Responsible Disclosure

Last updated:
2026-04-22
Effective:
2026-04-22

Security is a core responsibility. This page summarizes our security program and explains how to responsibly report vulnerabilities you discover.

On this page

  1. 1.Program overview
  2. 2.Authentication
  3. 3.Data protection
  4. 4.Responsible disclosure
  5. 5.Scope
  6. 6.Out of scope
  7. 7.Safe harbor
  8. 8.Bug bounty
  9. 9.Contact

1. Program overview

  • Transport: TLS 1.2+ for all client-server and inter-service traffic; HSTS is enforced on production origins.
  • At rest: customer data is encrypted at rest using modern symmetric algorithms (e.g., AES-256) managed by our cloud provider's KMS.
  • Access controls: least-privilege role-based access for production systems, protected by SSO and hardware-backed multi-factor authentication.
  • Auditing: we maintain audit logs of privileged actions with retention appropriate to risk.
  • Backups: automated, encrypted, and tested on a regular cadence.
  • Incident response: documented runbooks, pager-based on-call, post-mortems, and customer notification aligned to applicable breach-notification law.
  • Status: operational status is available at https://atlas.wrxstack.com/status; incident history is maintained at https://atlas.wrxstack.com/status/incidents.

2. Authentication

Passwords are hashed with a modern memory-hard algorithm (e.g., Argon2 or bcrypt with appropriate cost). Multi-factor authentication is available via TOTP, and optional backup codes. You can also sign in via Google, Microsoft, or GitHub OAuth.

3. Data protection

Application-level protections include CSRF tokens on state-changing requests, strict Content Security Policy on marketing pages, secure cookies, and rate limiting on sensitive endpoints. We follow OWASP ASVS guidance as an internal baseline.

4. Responsible disclosure process

  1. Email security@wrxstack.com with a detailed description, reproduction steps, and impact analysis. If you need encrypted coordination, follow the notice at https://atlas.wrxstack.com/.well-known/pgp-key.txt.
  2. We acknowledge within 3 business days, triage within 7, and target remediation proportionate to severity (critical issues prioritized immediately).
  3. Please do not publicly disclose the issue until we have had a reasonable opportunity to remediate - typically 90 days from acknowledgement, sooner by mutual agreement.

5. In-scope assets

  • The primary web application on our production domain.
  • Our public REST and sync APIs.
  • Our official mobile application.
  • Our marketing site and public documentation.

6. Out of scope

  • Denial-of-service attacks, load testing, or any attempt to degrade service.
  • Social engineering of employees, contractors, or users.
  • Physical attacks against offices, data centers, or personnel.
  • Findings that require privileged local access to a victim's device.
  • Vulnerabilities in third-party services or dependencies we do not control (report to the vendor instead).
  • Missing best-practice HTTP security headers on marketing pages without a demonstrable impact.

7. Safe harbor

We will not pursue legal action against good-faith security research that (a) complies with this policy, (b) stays within scope, (c) does not access, modify, or destroy data belonging to other users, (d) reports findings promptly, and (e) does not violate applicable law. If your research is conducted in good faith and in accordance with this policy, we will work with you to understand and remediate the issue, and we will consider your actions authorized under the U.S. Computer Fraud and Abuse Act and equivalent laws in other jurisdictions.

8. Bug bounty

Details of our coordinated disclosure scope, safe harbor, report requirements, and reward posture are maintained at https://atlas.wrxstack.com/security/bug-bounty. Monetary rewards are not guaranteed unless a separate written program term says otherwise.

9. Contact

Security: security@wrxstack.com. Please do not use support channels for vulnerability reports.