Skip to content
HorizonWorksGROUP
ATLAS Services Case study About Insights
Request a walkthrough

ATLAS · Trust Center

Security, data & support — in plain English.

Last reviewed: October 2, 2026

A school that runs on ATLAS is trusting us with its student records, its hours, and its ledger. This page describes how we actually run the platform today: what happens to your records, how they are protected and backed up, what support covers, and how you get your data out. Where something is decided school by school, we say so rather than guess.

On this page

  • Your data
  • Security
  • Hosting
  • Backup & recovery
  • Support & changes
  • Leaving ATLAS
  • Shared responsibility
  • Service providers
  • Our own six questions

Where this page fits

Four different documents answer four different questions. It helps to keep them apart.

  1. The ATLAS pageWhat ATLAS is, and why a school would want it. Read it →
  2. This Trust CenterHow we protect, operate, and support ATLAS today.
  3. Your proposalWhat we will fit and build for your school, on what timeline, at what price.
  4. Your agreementThe binding terms: rights, obligations, fees, and service commitments.

This page describes our practice. It is not a contract, a service-level agreement, or a certification, and it does not replace or override your agreement with us. If the two ever differ, your agreement governs.

Your data

ATLAS uses your school's records for one thing: running your school's system. The platform does not send them to advertisers, data brokers, or AI model providers, and there are no advertising or analytics trackers inside it.

We have said publicly that nobody should have to buy their way out of their own records. The formal terms — ownership, how long records are kept, and how they are deleted — belong in your agreement, not on a web page. Ask to see them before you sign.

Getting data out today

Authorized staff can export, on their own and at any time:

  • The student roster, with the contact, cohort, and status columns you choose (CSV).
  • The school-wide ledger — balances and every payment — and any single student's ledger (Excel).
  • A student's transcript (Word), one student at a time.
  • The audit log (CSV) and the attendance shortfall report (CSV).
  • Any uploaded document, in its original format.

Not everything has an export button yet. Gradebooks, full attendance history, and admissions records can be viewed and printed but not downloaded in bulk, and there is no single “export everything” control. A complete copy — the full database and every uploaded file — is not self-service; we would produce it for you. When, in what format, and at what cost are set in your agreement.

Security

Signing in

  • People sign in with Google. ATLAS stores no passwords.
  • Accounts are created by invitation only, and an invitation works only for the exact email address it was sent to.
  • Two-step verification is whatever each person's Google account has turned on. ATLAS does not add a second factor of its own.
  • Sessions end after eight hours and are held on the server, not in the browser.

Who can see what

  • Access is by role — administrator, lead teacher, teacher, teaching assistant, and student — and is enforced on the server for every request, not just hidden in the menus.
  • Financial management and school settings require the administrator role.
  • Your administrators invite staff and students and choose their role. Changing or removing an existing person's access is currently done by us, on your request.
  • The student, faculty, and administrator companion apps are read-only. The Scan Kiosk records attendance scans and nothing else, and each kiosk can be given its own key, which can be revoked without disturbing the others.

Encryption

  • Every connection to ATLAS is encrypted (HTTPS, TLS 1.2 or newer). Unencrypted requests are redirected.
  • The database and uploaded files are encrypted at rest by the hosting platform.
  • Uploaded files are private. They are reachable only through ATLAS, which checks who is asking.
  • Card numbers are entered on our payment processor's form and are never stored in ATLAS.

The audit trail

ATLAS keeps an append-only log of sign-ins, access invitations, student status changes, charges and payments, deleted financial records, and deleted documents — who, what, and when. Attendance corrections are logged separately. Administrators can read and export the log. It is a record of consequential actions, not a keystroke-level history of every edit.

How changes reach your system

  • Changes pass automated tests before every deploy, and normal releases run first in a staging environment with its own database.
  • Software dependencies are checked for updates weekly, and our build checks fail on a new high- or critical-severity advisory.
  • The code is scanned for security flaws nightly and for accidentally committed credentials on every change.

What we don't claim

We hold no security certifications such as SOC 2 or ISO 27001, and nothing on this page should be read as one. We would rather describe what we do than borrow language that sounds larger than a firm our size.

Hosting

  • ATLAS runs on Microsoft Azure, in data centers in the United States, on Azure's managed application, database, and storage services.
  • We deploy it, monitor it, and keep it patched. We keep written runbooks for failures in sign-in, email and text messaging, file uploads, and attendance scanning.
  • We do not publish an uptime figure. Any availability commitment would be in your agreement.

Backup & recovery

As ATLAS runs today:

  • Continuous database backup. The database can be restored to any point in the previous 35 days.
  • A weekly copy held somewhere else. Each week a full copy of the database and of every uploaded document is encrypted and stored with a separate provider outside Azure. We keep the last 8 weekly and 12 monthly copies of each. Every run reports whether it succeeded.
  • Uploaded files, day to day. Between weekly copies, documents sit on encrypted storage that keeps multiple copies within one Azure data center, and a deleted file can be recovered for seven days.

What a new school's deployment receives is set in its agreement. We do not publish recovery-time or recovery-point figures. If your school needs specific ones, they belong in your agreement, where they can be held to.

Support & changes

A school changes constantly. Most of that should never involve a developer, some of it involves us briefly, and a little of it is genuinely new software. It's worth knowing which is which before you start.

What your staff do themselves

  • Add students, edit their records, and move them through statuses.
  • Create cohorts, assign students, publish, and graduate them.
  • Post charges and payments, void or waive them, set up payment plans, and adjust fee amounts.
  • Build and revise the registration form and questionnaires.
  • Invite staff and students, and upload and manage documents.
  • Update the school's name, contact details, logo, and colors.

What we set up for you

The structure of your school — your program and its courses, hour requirements, the grading scale, attendance rules, the kinds of fees you charge, schedule patterns, and the wording of agreements and notices — is fitted by us during implementation. This is the “fitted, not templated” part of ATLAS. When one of these changes after launch, the change comes to us. Which of those are covered by your support plan and which are quoted is set in your agreement.

What is new work

A capability your ATLAS doesn't have — a new integration, a new workflow, a new kind of report — is custom development. We scope it and quote it before any of it is built.

Keeping it running

Hosting, monitoring, security updates, and fixing things that are broken are part of operating the platform. What your support plan includes is set in your agreement.

Reaching us

By phone at 704-459-1440 or by email at hello@thehorizonworksgroup.com. You reach the people who built your system, and we typically respond within one business day. That is our habit, not a guarantee; support hours and response targets are set in your agreement.

How pricing is structured

Every ATLAS is priced by proposal, because every school's fit is different. The layers are consistent: discovery and implementation; the platform subscription; managed support and maintenance; optional custom development; and professional services such as data conversion and training. How and why we price this way →

Leaving ATLAS

ATLAS is not meant to hold your records hostage. If you leave:

  • The exports listed above remain yours to run for as long as you have access.
  • We can produce a complete copy of your database and your uploaded files.
  • Backup copies containing your data are not kept forever: the off-site copies roll off within about twelve months.

What we do not settle on a web page: how long your system stays available after notice, when your live data is deleted and how that is confirmed, and what hands-on help with a move costs. Those are agreement terms. If a draft agreement from us doesn't answer them, ask — it should.

Shared responsibility

ATLAS supports compliance-oriented recordkeeping. It does not make a school compliant by being installed, and it does not replace your regulatory judgment or your board's review.

What we do

  • Operate, patch, and back up the platform.
  • Store what is entered, and apply the access rules your roles define.
  • Tell you plainly what the platform does and doesn't do.

What stays with your school

  • Knowing which state, federal, and accreditor rules apply to you, and meeting them.
  • Deciding who gets access, and telling us when someone leaves.
  • The security of the Google accounts your people sign in with.
  • The accuracy of what is entered, and your own notices to students.

Service providers

These are the outside services ATLAS relies on, and what reaches each. Which ones apply to your school depends on the features you use. Current as of October 2, 2026.

ProviderUsed forWhat it receives
Microsoft AzureHosting, database, file storageAll ATLAS data, encrypted at rest
GoogleSign-in; optional Classroom importSign-in identity; reads courses, rosters, and coursework from Classroom if you enable it
Twilio SendGridEmail deliveryRecipient addresses and message content
TelnyxText messaging, if enabledPhone numbers and message content
StripeCard payments, if enabledPayment amount, and the payer's email and card details entered on Stripe's form
Grafana CloudSystem health monitoringTechnical telemetry, with personal details filtered out
AtlassianStaff feedback and issue reportsWhat a staff member types into the feedback form, with their name, the page, and the browser
BackblazeOff-site backupEncrypted database copies

AI. We use AI to help build software, and we write about that openly. The running ATLAS platform sends no school or student data to any AI model provider.

Our own six questions

We tell organizations to put six questions to anyone who builds or maintains software for them — including us. Here are our answers for ATLAS, including the ones that are not yet as complete as we'd like.

When it breaks at 7am on the first day of a new term, who answers?
The people who built it, by phone or email, typically within one business day. Beyond that we publish no response targets; they are set in your agreement.
Who holds the credentials?
ATLAS is a platform we host and operate, so we run the infrastructure rather than handing it to you. That is the opposite of what we recommend for software you own outright, and it is why the export and exit terms matter more here. The hosting arrangement for your school, and which accounts sit in your school's own name, are set in your agreement.
Where does the source code live, and what happens to it if we stop working together?
ATLAS is our platform, and we keep developing it. Your rights in anything built specifically for your school are set in your agreement.
Can we export all of our data, including the parts that never appear on a screen?
Several exports are self-service today; a complete copy would be produced by us. The specifics are above, including what has no export button yet.
What is the update cadence, and who decides what gets updated?
Security and dependency updates are ours to make and don't wait for a conversation. Who decides on changes to how your school's ATLAS behaves is set in your agreement.
What does it cost to leave?
That is priced in your agreement, not discovered at the end. Ask us for the figure before you sign.

Questions this page doesn't answer

If you are evaluating ATLAS and need something more specific than this page gives — for a board, an accreditor, or your own peace of mind — ask us directly. We would rather answer a hard question now than have you find the answer later.

The Horizon Works Group
Email: hello@thehorizonworksgroup.com
Phone: 704-459-1440

The public website's own Privacy Policy, Cookie Notice, and Terms of Use cover thehorizonworksgroup.com, not ATLAS.

HorizonWorksGROUP
ATLAS Trust Center Services About Insights Request a walkthrough
Privacy · Terms · Accessibility · Cookies
QLD Holdings LLC, d/b/a The Horizon Works Group · 108 JW Borders Dr., Shelby, NC 28150 · 704-459-1440 · hello@thehorizonworksgroup.com © The Horizon Works Group · Software that runs the real work.