Skip to content

Security

ATLAS is designed for operational security. All your data is encrypted and stays on your device.


All sensitive data is encrypted at rest using AES-256-GCM:

  • Projects, cards, notes, and POIs
  • GPS coordinates
  • Situational awareness data
  • PM3 dump files (when app is backgrounded)

Keys are stored in the Android Keystore (hardware-backed when available).


ATLAS does NOT transmit operational data to our servers:

  • GPS locations
  • Card data or reads
  • Project files
  • Notes or POIs
  • Any captured data

All operational data stays on your device.


Warning: We do not recommend running ATLAS on rooted devices.

Rooted devices have weakened security boundaries that can expose your operational data. Android’s security model relies on app isolation that root access bypasses.

  • Unrooted deviceGrapheneOS recommended for enhanced security
  • Full disk encryption — Enable in Android settings
  • Strong PIN or passphrase — Avoid biometrics (courts can compel fingerprint/face unlock, but not PIN disclosure)
  • Up-to-date OS — Latest security patches
  • Dedicated device — Separate from personal use if possible

By default, ATLAS blocks screenshots and screen recording to prevent accidental data exposure.

To toggle: Settings → Security → Screenshot Protection


ATLAS actively monitors its own integrity and will alert you to potential security issues.

The app continuously verifies it hasn’t been modified:

  • Signature Verification — Validates the app is signed by Mayweather Group
  • Integrity Checks — Detects unauthorized code modifications
  • Debugger Detection — Identifies if debugging tools are attached
  • Root Detection — Warns when running on rooted devices

If tampering is detected, ATLAS will:

  1. Display a clear warning to you
  2. Log the security violation
  3. Restrict sensitive functionality
  4. Report the incident to our security monitoring

Check your device’s security posture anytime:

Settings → Security → View Security Status

This screen shows:

  • Overall security level (Secure / Warning / Critical)
  • Encryption status and key storage
  • Tampering detection results
  • Root/debugger detection status

  • Enable screenshot protection
  • Verify device encryption is on
  • Clear any sensitive data from previous engagements
  • Set an active project to tag data automatically
  • Use GPS tagging for all card reads
  • Take notes while details are fresh
  • Export project data for reporting
  • Securely delete local data when complete

To permanently delete data:

  1. Open the item (project, card, note)
  2. Long-press and select Delete
  3. Confirm deletion

Deleted data is overwritten and cannot be recovered.

For full device wipe: Use Android’s factory reset.


Found a security vulnerability? Contact us at [email protected]