Endpoints that do not exist

  • No telemetry, analytics, or crash reporting
  • No license server: AtlasOA keys are verified locally; Atlas K-12 has no license check
  • No update server or update check
  • No hosted AI service (OpenAI, Anthropic, Google, or any other)
  • No connection to AtlasOA, LLC

Inbound

ProductDefaultNetwork access
AtlasOAHTTP on TCP 5000, listening on all interfaces. The installer offers a Windows Firewall rule for port 5000, unchecked by default.Recommended: keep 5000 closed to the network and publish the application through a reverse proxy on TCP 443 (HTTPS) with your certificate.
Atlas K-12HTTP on TCP 5050, listening on the server only (127.0.0.1).Choose a network mode: local only; your internal network over plain HTTP (a startup warning appears); or behind a reverse proxy on TCP 443 (HTTPS), which also turns on secure cookies and HSTS.

Restrict inbound access to your staff networks and VPN. Neither product has a built-in IP allowlist; use your firewall or reverse proxy.

Outbound (all optional)

PurposeProductDestinationPort / protocolWhat is sent
Jenzabar J1 / EX syncAtlasOAYour SQL ServerTCP 1433 (or your port), encryptedRead-only queries
LMS sync (Canvas, Blackboard, Moodle, Jenzabar CX)AtlasOAYour LMS or API addressTCP 443, HTTPSAn API token (Canvas, Moodle) or client credentials to obtain a token (Blackboard, Jenzabar CX), then read requests. Moodle sends its token in the request address.
SIS sync (API connectors, OneRoster, Ed-Fi)Atlas K-12 (fetcher process)Your SIS address, as configuredTCP 443, HTTPSAn API key (Aeries, Synergy) or client credentials to obtain a token (others), then read requests
SFTP file intakeAtlas K-12 (fetcher process)Your SFTP serverTCP 22Login, then file downloads; unknown host keys are rejected
Email alertsBothYour SMTP server or relayTCP 587 (STARTTLS) or 465 (AtlasOA)Alert messages. AtlasOA alerts contain course and outcome summaries, not student names. Atlas K-12 tier-change alerts contain the student's name, grade, area, and old and new tier. Atlas K-12's outbound guard may require a relay on the server itself; confirm during evaluation.
Offsite backupAtlasOAYour network share, SFTP server, or S3-compatible storageSMB, TCP 22, or TCP 443Backup files
Single sign-onAtlas K-12login.microsoftonline.comTCP 443, HTTPSStandard OpenID Connect sign-in exchange and Microsoft's public signing keys. Allowed only while single sign-on is enabled and fully configured.
Strategy library link checks and cachingAtlas K-12 (fetcher process)An allowlist of 8 public research organizations: IRIS Center (Vanderbilt), IES What Works Clearinghouse, PBIS World, CASEL, Attendance Works, Intervention Central, Reading Rockets, and Understood.orgTCP 443, HTTPSPage addresses and a user agent; never student data. Administrators can turn sources off.
Building health checkAtlas K-12 (separate scheduled tool)Each school's status page address, if you configure oneHTTP(S)A status request

With every optional feature off, both products work with all outbound traffic blocked. Atlas K-12 also enforces this in software: its main application refuses non-local connections and logs each attempt.

At startup, AtlasOA learns its own network address by opening a UDP socket toward 8.8.8.8. No packet is sent; it only reads which local interface would be used. Some monitoring tools may still show the lookup.

Requests made by staff browsers

These come from staff computers, not the server, when someone opens the application:

  • fonts.googleapis.com and fonts.gstatic.com: the Inter typeface (both products).
  • cdn.jsdelivr.net: the Chart.js charting library (Atlas K-12).

They carry the browser's IP address and user agent, and no application data. If you block them, pages use system fonts, and Atlas K-12 charts may not display. See Subprocessors.

DNS

  • Create an internal DNS name for the server (for example atlas.yourdistrict.local) and point your reverse proxy certificate at it.
  • External DNS is needed only for the optional outbound features above.

Air-gapped installations

Atlas K-12 supports fully air-gapped sites: bring the installer and model files in on removable media. In that configuration, SIS API sync, single sign-on, the strategy library's link checks, and browser font and chart downloads are unavailable. Use CSV imports and local accounts.

Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.