Trust
Security at Creative Strategies Atlas
Last updated October 8, 2026
This page describes application controls and the evidence needed to assess them. Enterprise integrations are staged and require a reviewed rollout.
Application access
Atlas supports passkeys and server-side session, entitlement and administrative checks. Atlas Agent Pro is available to entitled subscribers and admins; privileged administration has separate guards. Public chat sharing exposes a limited read-only projection.
AI and diagnostic data
Agent code routes generation through OpenRouter to selected models. Separate knowledge-base and helper paths also use Vercel AI Gateway and Google services. Application history and configured OpenRouter Broadcast tracing can contain conversation content. Vendor retention, training terms and account settings require verification for the intended deployment. Do not assume zero retention.
Enterprise integration status
Company policies, roles, audit views, OIDC customer login and limited existing-account SCIM integration code are staged with enterprise activation disabled by default. Production rollout requires operator configuration, administration workflows and acceptance testing. Content export/deletion has synthetic tests; external storage adapters and scheduled retention remain incomplete. Sign in with Atlas is an outbound identity feature and does not provide customer SSO.
Procurement evidence
Ask for the current processor inventory, access review, restore-test evidence and incident procedures before approving an enterprise rollout. Certifications, contractual terms, service guarantees and encryption coverage must be supported by current evidence; this page makes no SOC 2 certification claim. Legal and DPA drafts require counsel review.
Report a concern
Contact max@creativestrategies.com privately with the affected feature, reproduction steps and impact. Avoid sending credentials or unnecessary customer data. See the privacy policy for data-request contact details.