Subprocessors

Last updated

Atmos runs on a short list of service providers. Each has a written agreement with us and receives only what its job needs. This page describes the categories we use. The named list and our security documentation are shared through a trust review.

There is no AI subprocessor

No large language model provider, no model hosting service and no artificial intelligence vendor processes data for Atmos. No customer code, no findings, no traces and no personal data are sent to a model provider by the scanner, by the editor extension or by the platform. Nothing we hold is used to train a model. The analysis is static and rule based, which is also why the same code gives the same result, every run.

The categories

  • Cloud infrastructure. Hosting, compute and storage for the platform and this website, and delivery of release downloads.
  • Managed database. Workspace records, findings and audit logs.
  • Payment processing. Collects card details directly at checkout. Card numbers never reach our systems.
  • GitHub. Sign-in, the Atmos GitHub App for pull request checks and comments, and verification that a repository is public.
  • Transactional email. Workspace invitations, confirmations and account notices.

Trust review

The named subprocessor list, with what each provider receives and where it processes, and our security documentation are available to customers and to teams evaluating Atmos. Request access at support@atmoslab.dev. We verify who you are, and we may ask you to accept confidentiality terms before we share security documentation. The Data Processing Addendum carries the subprocessor mechanics.

What is not on the list

Today we use no analytics provider, no advertising network, no session recording, no error reporting service that receives customer data, and no data broker.

Changes

Before a new subprocessor starts processing customer personal data, we notify workspace owners by email, naming it. If you object on reasonable data protection grounds, write to support@atmoslab.dev. We will work with you to find a solution, and if there is none you may terminate the affected subscription.