Security Policy
Effective Date: February 21, 2026 · BlackAtlas LLC
Our Commitment to Security
Security is foundational to everything we build. BlackAtlas products are designed for operators who depend on their tools in critical situations. We take the security of our products, services, and customer data seriously.
Responsible Disclosure
We welcome reports from security researchers who discover vulnerabilities in our products or website. If you believe you have found a security vulnerability, please report it responsibly:
- Email: info@blackatlas.tech
- Include a detailed description of the vulnerability and steps to reproduce
- Allow reasonable time for us to investigate and address the issue before public disclosure
- Do not access, modify, or delete data belonging to other users
We will acknowledge receipt of your report within 48 hours and provide an estimated timeline for resolution. We will not pursue legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.
Product Security
AtlasRF: All AtlasRF units run on a hardened Linux base with minimal attack surface. AtlasRF is passive and receive-only — it does not transmit on the bands it monitors. Web dashboard access is restricted to the local network by default. CoT data streams support encryption in transit. No data is transmitted to BlackAtlas or any third party. AtlasRF is region-locked in software and will not operate outside the United States.
GridDown Maps: GridDown operates entirely offline by design. No user data leaves the device, and map tiles and navigation data are stored locally. GridDown Maps performs no cryptography of its own: plan and team packages are serialised JSON, base64-encoded for safe transport, and anyone holding the file can read it. Where confidentiality is required, transfer over a link that encrypts — the GridDown Secure Messenger firmware and Meshtastic both encrypt on the radio. GridDown Maps sends no telemetry and has no cloud backend, so there is no server-side data to expose.
GridDown Sensor Hub: The Sensor Hub is passive and receive-only on every band it monitors. All processing happens on the device and on your own network — there is no cloud backend and no account, so there is no BlackAtlas-side copy of your data. Software updates are cryptographically signed and applied from a bundle you upload, with an automatic rollback if an update fails; a hub deployed off-grid never needs an internet connection to stay current.
GridDown Secure Messenger: The firmware provides message confidentiality using standard, published algorithms — AES-256-GCM for group and direct traffic, ephemeral ECDH on NIST P-256 for per-peer forward secrecy, PBKDF2-HMAC-SHA256 for key derivation, and HMAC-SHA256 for authenticated delivery confirmations and remote-wipe commands — all via mbedTLS, with no proprietary or unpublished algorithm. Because the firmware is open source under GPL-3.0-or-later, the cryptography is auditable by anyone. There are no accounts, no registration, and no infrastructure to compromise.
AtlasGate: AtlasGate routers run OpenWrt with WireGuard and OpenVPN support. Administration is local by default, and no configuration or traffic data is sent to BlackAtlas.
AtlasGuard: AtlasGuard is a passive RF-awareness device. It operates fully offline with no cloud service and no account, and detections stay on your device.
AtlasBridge: AtlasBridge translates sensor data into your own command-and-control environment. It is vendor-neutral and routes data on infrastructure you control; BlackAtlas is not an intermediary in those connections.
Infrastructure Security
- Website served via Cloudflare with DDoS protection, WAF, and TLS 1.3
- No customer data stored on the web server (static site architecture)
- Payment processing handled entirely by Stripe (PCI DSS Level 1 certified)
- Email communications secured via TLS
- Source code repositories use branch protection and required reviews
Data Handling
Our products are designed with a zero-cloud-dependency philosophy. AtlasRF and GridDown process all data locally on the device. We do not operate telemetry, analytics, or data collection services within our hardware products. Your operational data stays on your hardware.
Supply Chain Security
Country of origin varies by product and by configuration, and we state it per product rather than making a blanket claim:
- AtlasGuard — designed and assembled in Virginia, USA.
- AtlasGate Pro — made in the USA by an ISO 9001 / AS9100 certified manufacturer. AtlasGate Home — assembled from allied-nation components and integrated in the US.
- AtlasRF and the GridDown Sensor Hub — built to order in the United States from commercial off-the-shelf components of mixed origin, including US, allied-nation, and other commercial sources. Passive receivers in particular are commercial parts whose origin varies by configuration.
- GridDown Maps is software developed in the United States and supplied with BlackAtlas hardware bundles. The GridDown Secure Messenger firmware is open-source software developed in the United States; BlackAtlas does not sell the third-party radio hardware it runs on, and that device is sourced and classified by its own seller.
We maintain traceability of our supply chain and prioritize vendors who are not covered entities under 47 U.S.C. § 889. For federal or defense procurement, contact us for a country-of-origin and TAA statement for your specific configuration — we will not represent a build as domestic when its components are not.
Incident Response
In the event of a security incident affecting customer data or product integrity, we will:
- Investigate and contain the incident promptly
- Notify affected customers within 72 hours of confirmed impact
- Provide clear information about what happened and recommended actions
- Implement corrective measures to prevent recurrence
Contact
Security inquiries and vulnerability reports:
info@blackatlas.tech