← Home
Legal

Security Policy

Effective Date: February 21, 2026  ·  BlackAtlas LLC

Our Commitment to Security

Security is foundational to everything we build. BlackAtlas products are designed for operators who depend on their tools in critical situations. We take the security of our products, services, and customer data seriously.

Responsible Disclosure

We welcome reports from security researchers who discover vulnerabilities in our products or website. If you believe you have found a security vulnerability, please report it responsibly:

We will acknowledge receipt of your report within 48 hours and provide an estimated timeline for resolution. We will not pursue legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.

Product Security

AtlasRF: All AtlasRF units run on a hardened Linux base with minimal attack surface. AtlasRF is passive and receive-only — it does not transmit on the bands it monitors. Web dashboard access is restricted to the local network by default. CoT data streams support encryption in transit. No data is transmitted to BlackAtlas or any third party. AtlasRF is region-locked in software and will not operate outside the United States.

GridDown Maps: GridDown operates entirely offline by design. No user data leaves the device, and map tiles and navigation data are stored locally. GridDown Maps performs no cryptography of its own: plan and team packages are serialised JSON, base64-encoded for safe transport, and anyone holding the file can read it. Where confidentiality is required, transfer over a link that encrypts — the GridDown Secure Messenger firmware and Meshtastic both encrypt on the radio. GridDown Maps sends no telemetry and has no cloud backend, so there is no server-side data to expose.

GridDown Sensor Hub: The Sensor Hub is passive and receive-only on every band it monitors. All processing happens on the device and on your own network — there is no cloud backend and no account, so there is no BlackAtlas-side copy of your data. Software updates are cryptographically signed and applied from a bundle you upload, with an automatic rollback if an update fails; a hub deployed off-grid never needs an internet connection to stay current.

GridDown Secure Messenger: The firmware provides message confidentiality using standard, published algorithms — AES-256-GCM for group and direct traffic, ephemeral ECDH on NIST P-256 for per-peer forward secrecy, PBKDF2-HMAC-SHA256 for key derivation, and HMAC-SHA256 for authenticated delivery confirmations and remote-wipe commands — all via mbedTLS, with no proprietary or unpublished algorithm. Because the firmware is open source under GPL-3.0-or-later, the cryptography is auditable by anyone. There are no accounts, no registration, and no infrastructure to compromise.

AtlasGate: AtlasGate routers run OpenWrt with WireGuard and OpenVPN support. Administration is local by default, and no configuration or traffic data is sent to BlackAtlas.

AtlasGuard: AtlasGuard is a passive RF-awareness device. It operates fully offline with no cloud service and no account, and detections stay on your device.

AtlasBridge: AtlasBridge translates sensor data into your own command-and-control environment. It is vendor-neutral and routes data on infrastructure you control; BlackAtlas is not an intermediary in those connections.

Infrastructure Security

Data Handling

Our products are designed with a zero-cloud-dependency philosophy. AtlasRF and GridDown process all data locally on the device. We do not operate telemetry, analytics, or data collection services within our hardware products. Your operational data stays on your hardware.

Supply Chain Security

Country of origin varies by product and by configuration, and we state it per product rather than making a blanket claim:

We maintain traceability of our supply chain and prioritize vendors who are not covered entities under 47 U.S.C. § 889. For federal or defense procurement, contact us for a country-of-origin and TAA statement for your specific configuration — we will not represent a build as domestic when its components are not.

Incident Response

In the event of a security incident affecting customer data or product integrity, we will:

Contact

Security inquiries and vulnerability reports:
info@blackatlas.tech