Security Overview

Last updated: August 11, 2026

This page summarizes how Atom is built, what data flows through the product, and the security practices used to protect customer information.

1. Product Architecture

Atom is a desktop plugin for Adobe Premiere and After Effects. Most product activity happens on the customer's computer, inside the selected Adobe app, and through the customer's selected AI provider setup.

Atom does not proxy AI traffic, store AI provider credentials on Atom servers, or add usage fees on top of the AI provider. AI usage is handled through OpenAI Codex, Anthropic Claude Code, or the model provider the customer configures through OpenCode.

2. Data Sent to AI Providers

When a customer uses Atom's AI features, the customer-selected AI provider may receive prompts, chat messages, project structure, layer names, properties, expressions, rendered composition preview frames, and files the customer explicitly attaches.

Atom does not automatically upload full-resolution source footage or final renders. Depending on the selected security mode and the requested task, the local agent may read files and send relevant contents to the selected AI provider.

3. Agent Access Modes

Atom provides Adobe Only, Project Folder, and Full Access modes for built-in chat. Raw ExtendScript remains available in every mode; the modes control the agent's separate shell and general file tools.

Adobe Only removes shell and general file tools. Project Folder uses the folder containing the saved Adobe project and adds shell commands plus file access there. On native Windows, Claude commands are not sandboxed and Atom displays a warning. Full Access allows unrestricted shell commands and files available to the customer's operating-system account. Detailed behavior and Adobe-specific limitations are documented in the Security Modes guide.

4. Data Stored by Atom

Atom stores only the data needed to operate the product, including purchase email, license/entitlement records, seat count, device seat identifiers, support messages, and optional feedback reports.

Feedback reports are customer-initiated. When submitted, Atom uploads the customer's written description plus encrypted chat logs and tool activity for that chat. Project files are not uploaded by the feedback flow.

5. Local Storage and Encryption

  • Customer AI provider keys are stored locally and encrypted on the customer's device.
  • Local diagnostic logs are written encrypted at rest.
  • Optional feedback logs are encrypted before upload.
  • Website and service connections use HTTPS where applicable.

6. MCP and Local Integrations

Atom's MCP Mode starts a local server on 127.0.0.1 so compatible local tools can control After Effects through Atom. It is designed for local-machine integrations, not public network access.

The local MCP server checks local host/origin information and is stopped when MCP Mode is turned off.

7. Access Controls

Access to Atom-operated customer systems is limited to the product operator and only used for product operation, support, security, billing, and legal obligations.

8. Incident Response

If we confirm a security incident that affects customer personal data processed by Atom, we will notify affected customers without undue delay and, where feasible, within 72 hours.

9. Certifications

Atom does not currently maintain SOC 2, ISO 27001, HIPAA, or FedRAMP certification. If a customer requires a formal security questionnaire, contact us and we will respond based on the current product architecture.

10. Contact

To report a security issue or request a security review, email hey@davey.design.