Security & Responsible Disclosure

Last updated: July 4, 2026

In short: ATARS is built privacy-first — your data is processed on your own computer, offline. Found a vulnerability? Report it responsibly and we will work with you to fix it.

1. Our approach

Security and privacy are designed in from the start. The desktop application processes datasets locally on your machine, disables usage-stat gathering, and makes external AI calls only when you supply your own key. See the Privacy Policy and Data Usage Policy for detail.

2. Practices

3. Responsible disclosure

If you believe you have found a security vulnerability, we appreciate a private, responsible report. Please:

Acting in good faith under these guidelines, we will not pursue action against you for your research, and we will credit you if you wish once the issue is resolved.

4. What is in scope

The ATARS application and this website. Out of scope: third-party services we link to, your own chosen AI provider, and issues that require physical access to your device.

5. How to report

Send details through the contact page and mark it as a security report. We aim to acknowledge valid reports promptly.

6. No warranty

We work hard on security, but no system is perfectly secure. Please handle sensitive data with appropriate care, as described in our Terms and Disclaimer.