Security

Security Policy.

At ATARIS we take security of our users' data very seriously.

Last updated · September 9, 2026

Although we take great care and effort to maintain secure code and practices, it is the nature of software development that exploits and security issues will arise.

Report a Vulnerability

If you find a security issue with a credible potential impact on ATARIS or its users, please contact security@atar.is immediately, so that we can fix it before public disclosure.

Include clear steps to reproduce the issue and explain its potential impact. Use only accounts and test data you control. Do not access, copy, modify, expose, or leak actual user data to demonstrate a vulnerability. If you encounter user data accidentally, stop testing immediately and report the issue without including that data in your report.

Bug Bounty Program

We are happy to offer bug bounties to security researchers with valid findings that have actual potential to affect the security of the platform or its users. Please reach out to discuss your findings and potential rewards.

Findings from automated vulnerability scans will not be considered unless they are validated and demonstrate real potential impact on ATARIS. Scanner output alone, theoretical issues, and best-practice recommendations without a credible impact are not eligible.

Our Security Practices

  • All data is encrypted in transit using TLS
  • User passwords are hashed using industry-standard algorithms
  • Regular security audits and code reviews
  • Strict access controls for internal systems
  • Automated vulnerability scanning

Contact

For security-related inquiries, please contact security@atar.is. For general inquiries, please use contact@atar.is.