Your server. Your database. Your network.
AtlasOA and Atlas K-12 are installed software, not a hosted service. The application, its database, and every uploaded file live on a machine your institution controls. AtlasOA, LLC does not operate a central database of your records.
Last reviewed: September 2026
The picture
Where your data lives
| Item | AtlasOA | Atlas K-12 |
|---|---|---|
| Application | Windows desktop build under Program Files, or a Windows service installed from source | Windows desktop build under Program Files |
| Database | One SQLite file, database.db, in %LOCALAPPDATA%\AtlasOA for the installed build | One SQLite file, atlas_k12.db, in %LOCALAPPDATA%\AtlasK12 |
| Uploaded files | uploads\ beside the database (attachments, evidence portfolio) | uploads\ beside the database (report cards, strategy resources) |
| Built-in backups | backups_db\ beside the database | backups\ beside the database |
| Audit log | A separate hash-chained SQLite file, audit_log.db. In the installed build it currently sits in the application folder rather than the data folder; see Known limitations. | A hash-chained table inside the main database |
| AI model | None. AtlasOA has no AI model and makes no AI calls. | A local model file loaded by the application on your server |
All of these are ordinary files on your disk. Encryption at rest comes from your disk encryption (for example BitLocker); the applications do not encrypt the database themselves. Stored integration and email passwords are encrypted by the application. See Encryption.
Does AtlasOA, LLC keep a copy?
No. There is no AtlasOA cloud, no central student database, no telemetry, and no crash reporting. Neither application contacts us for licensing or updates. We only see institutional data if your staff choose to send it to us, for example by attaching a file to a support email. We ask you not to send student records; describe the problem or use sample data instead.
How the application runs
- AtlasOA listens on port 5000 over plain HTTP on all network interfaces. The installer offers an optional Windows Firewall rule for that port, unchecked by default. With Windows Defender Firewall on and no other rule allowing it, the port is reachable only from the server itself; if Windows asks to allow network access on first run, decline unless you intend to expose it. For access across your network, put it behind a reverse proxy that provides HTTPS.
- Atlas K-12 listens on
127.0.0.1:5050by default (the server only). A network mode setting chooses between local only, your internal network over plain HTTP (with a startup warning), or behind a reverse proxy that provides HTTPS. - Neither application terminates HTTPS itself. HTTPS is provided by a reverse proxy such as IIS. See Network requirements.
What connects outward
With default settings, neither application sends institutional data anywhere. Optional features you configure connect to destinations you choose: your SIS or LMS, your email relay, your offsite backup location, and (Atlas K-12) Microsoft Entra ID for single sign-on and a short allowlist of public research websites used by the strategy library. Atlas K-12 enforces this in software: the main application refuses outbound connections, and research-site and SIS connections go only through a separate fetcher process restricted to an allowlist. The optional building health check runs as its own scheduled tool. The complete list is on Network requirements.
Who controls what
Your institution controls
- The server, operating system, and network
- Who can reach the application
- The database, files, and backups
- User accounts and roles
- Which integrations are turned on
- When updates are installed
AtlasOA, LLC controls
- The application code and its security controls
- Releasing updates and security fixes
- Documentation and support
- Nothing on your server: the software contains no remote-access capability for AtlasOA, LLC
The full split is on Shared responsibility.
How updates reach you
Updates are new installers that your IT staff download and run when they choose. Neither product updates itself or checks for updates. See Updates and patching.
Supported deployment shapes
- Internal network only, with VPN for off-site staff.
- A public address behind your reverse proxy with HTTPS (Atlas K-12 adds Microsoft Entra single sign-on for this shape).
- Atlas K-12 also documents site-to-site VPN and fully air-gapped installations.
- Not supported: hosted SaaS, Docker or Kubernetes, Linux or macOS servers, and one installation shared by several institutions.
Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.