1. What you are agreeing to
These terms cover your use of Atlas — the web workspace at this address, the agent you run on your own machine, and the analyser inside it. Using any of them means you accept these terms. If you do not accept them, do not use it.
If you are using Atlas for an employer, you are confirming that you may accept these terms on their behalf.
2. What you may point it at
Only code and systems you own, or have permission to work with. Atlas reads any directory you choose and sends requests to any host you name, so the responsibility for those choices is entirely yours. Using it against systems you are not authorised to test breaches these terms and may be unlawful where you are.
You also agree not to:
- Use it to attack, overload or disrupt any service, yours or anyone else’s.
- Extract, decompile or redistribute the analyser, or attempt to run it outside Atlas.
- Resell access to Atlas, or present it as your own product.
- Automate the hosted site in a way that degrades it for others — the import endpoint in particular is rate limited, and circumventing that is a breach.
3. Accounts and the mailing list
Atlas does not require an account to scan, test, save or export. Where an account exists, you are responsible for keeping its password secret and for what happens under it. If you give us an email address for release notes, you can remove it at any time using the unsubscribe link in any email we send.
4. Your work stays yours
Source code, analysis results, collections, captured responses, environment values and documentation are yours. Nothing in these terms transfers any right in them. Because they are written to your own disk and your own browser, we hold no copy and could not act on them if we wanted to — see the privacy policy for exactly what exists and where.
Your collections and documentation are stored in formats you can read and in a repository you own, so nothing you build here depends on continued access to this service.
5. What the analysis is, and is not
The analyser reads code without running it. That makes it fast and repeatable, and it also makes it approximate. It can miss a route registered dynamically, misread an unusual pattern, or report an endpoint as unprotected when a gateway in front of it enforces authentication.
Findings are prompts to go and look, not a certification that anything is safe. Do not treat a clean report as evidence that an application has no vulnerabilities, and do not treat this tool as a substitute for code review or penetration testing.
6. Requests you send
The request panel sends real HTTP requests to real servers. A request that deletes something will delete it, and a flow that runs ten of them will run all ten. Check the method, the target and the selected environment before you send, particularly when a production base URL is active. Atlas will not second-guess a request you asked it to make.
7. The agent
The agent is a process you start yourself on your own machine. While it runs it reads the project folder you select, forwards the requests you send, and runs Git commands limited to the .atlas.api/ directory inside that folder. It listens only on 127.0.0.1, accepts only this site, and requires a token that changes every time it starts. Stopping it removes all of that access.
8. Third parties
Optional features depend on services we do not operate — GitHub for importing a repository, your own Git remote for committing, an email provider for release notes. Those can change or fail independently of Atlas, and their terms apply to your use of them.
9. Availability
Atlas is provided as is. Features may be added, changed or removed, and no uptime or fitness for a particular purpose is promised. Where a feature is described as early or approximate, treat it that way.
10. Liability
To the fullest extent the law allows, we are not liable for lost data, lost profits, or any indirect or consequential damage arising from use of Atlas — including damage caused by a request you chose to send, by a Git command you asked for, or by relying on an analysis result. Nothing in these terms limits liability that cannot be limited by law.
11. Licensing and ownership
The Atlas agent is open source under the MIT licence, and you are free to read, modify and run it. The analyser it contains is proprietary, is distributed only as a build artifact, and is licensed to you for use with Atlas — it may not be extracted, reverse engineered or redistributed. Atlas, its name and its interface remain ours.
12. Ending it
You can stop using Atlas at any time; deleting .atlas.api/ and clearing this site’s data removes everything on your side. We may withdraw access to the hosted site from anyone who breaches section 2. Sections 4, 5, 10 and 11 survive.
13. Changes
These terms may be updated. The date at the top of this page is the current version, and continuing to use Atlas after a change means you accept it.