ATLAS TEK
Customer Portal Talk to us
Zero-Trust AI · On-Premise · DoW-Ready

Your enterprise is heavy.
ATLAS carries the weight.

The first AI IT operations platform that runs entirely on your network. No cloud. No data egress. No air-gap compromise.

DETECT REPAIR DOCUMENT
DETECT
Correlate ACAS, MDE, Splunk, Forescout, and AD in one timeline. Surface the 20 alerts that matter from the 2,000 that don't. Insider threat detection with behavioral baselining and LLM correlation - 32 CFR 117 compliant.
REPAIR
Air-gap-signed multi-disk updates. Days, not weeks. RSA-SHA384 verified. Every action rollback-safe.
DOCUMENT
STIG compliance, ACAS findings, PQC readiness, audit trail. Pull a report in 60 seconds - or before an inspection.
The signal-to-noise ratio

Your analysts don't need more alerts. They need the right ones.

2,000 20
alerts per day · surfaced to humans
The LLM has no outbound network access. By architecture, not policy.
The WebGateway Architecture Process isolation. By design. Not by policy. CUSTOMER NETWORK · TRUST ZONE ENDPOINT AGENTS Windows agent · telemetry Linux systemd · syslog Linux launchd · unified log mTLS · HMAC-SHA256 ATLAS HUB your enterprise Admin Console 15 tabs client-cert auth Orchestration · FastAPI · PostgreSQL 16 · Redis · pgvector · Playbook engine · ACAS · AD · STIG · UAM Local LLM tri-LLM deep + fast + console NO NET WEBGATEWAY Sanitization Layer strips: hostnames IPs · FQDNs DoW naming PROCESS ISOLATION in-process EXTERNAL · UNTRUSTED Public LLM APIs OpenAI · Anthropic Threat Intel Feeds CISA KEV · NVD AI has no direct access sanitized IN-PROCESS SANITIZATION · mTLS · HMAC-SHA256 · EVERY QUERY LOGGED in-zone data flow untrusted boundary LLM has no network access (process isolation)
Process isolation
The LLM runs in a process with no outbound network access. The AI physically cannot bypass the gateway.
Cryptographic signing
Every air-gap package is signed with RSA-SHA384. Multi-disk, numbered, verified before ingest.
Cross-signed CA rotation
Annual CA rotation, cross-signed by the old CA. Classified hubs accept the new trust anchor via USB - zero network contact.
CSR-based cert auto-renewal
Agent certificates renew automatically via CSR exchange. Private keys never leave the agent. STIG-compliant per NIST SP 800-57 and DoDI 8520.02.
Per-agent trust levels
Every agent has a trust level (read-only, write, admin). Hub enforces it. Agent enforces it too - defense-in-depth. Self-agents locked to read-only.
HMAC-SHA256 command signing
Every command dispatched to an agent is cryptographically signed. Unsigned or tampered commands are rejected before execution.
Full audit trail
Every command, cert renewal, agent update, and admin action is logged with actor, target, timestamp, and result. Pull a report in 60 seconds.
Post-Quantum Readiness

The quantum deadline is January 2027.

CNSA 2.0 mandates PQC-capable acquisitions starting next year. ATLAS scans every endpoint - certificates, TLS configs, SSH keys, crypto libraries - and tells you exactly what is vulnerable and what to do about it.

543
Assets scanned
521
Quantum-vulnerable
0%
PQC migration progress
6 mo
Until CNSA 2.0 deadline
NOW - Automatable

Enable hybrid post-quantum key exchange in SSH. Disable weak TLS cipher suites. Inventory all crypto assets across every endpoint. ATLAS executes these via HMAC-signed commands today.

NEXT - Plan and Stage

Upgrade OpenSSL to 3.5+ with native ML-KEM and ML-DSA support. Prepare CA infrastructure for ML-DSA certificate issuance. Stage CSRs and test PQC certificate chains.

FUTURE - Standards Pending

Replace SSH host keys with ML-DSA signatures when OpenSSH adds support. Full PQC certificate rollout across infrastructure. Standards still being finalized by IETF and NIST.

FIPS 203 (ML-KEM) · FIPS 204 (ML-DSA) · FIPS 205 (SLH-DSA) · NIST SP 800-208 · DoDI 8520.02

Insider Threat Detection

Insider threats don't phone home. Neither does ATLAS.

32 CFR 117 mandates User Activity Monitoring on every cleared facility's classified network. But every commercial UAM tool needs cloud. ATLAS runs entirely on-prem and air-gap - behavioral baselining, indicator detection, LLM correlation. No phone-home. No external dependencies.

30+
Windows event types monitored
24
CDSE/MITRE indicators
0
Cloud connections required
30 mo
NARA GRS 5.6 retention
Behavioral Baselining

30-day rolling statistical profiles per user. Login hours, file access patterns, application usage, USB events, command history. No ML or GPU required - works on air-gap systems with zero external dependencies.

LLM-Enhanced Correlation

Rule-based FAST path catches known patterns on every event. LLM DEEP path correlates across events: "User logged in at 0300, accessed 47 files across 3 classified directories, compressed them, then inserted a USB device" - one case file, not four separate alerts.

ISSO Dashboard

Dedicated UAM card with high-risk user risk scores, clickable insider threat indicators, investigation case files with session reconstruction. DCSA audit-ready export. ISSO and admin roles only.

32 CFR 117 · DoDI 5205.16 · EO 13587 · NARA GRS 5.6 · NARA GRS 4.6 · CDSE Insider Threat Indicators · MITRE UAM Research

Compliance Automation

From STIG scan to remediated finding - without a spreadsheet.

ATLAS reads DISA STIG fix text, generates real remediation commands (PowerShell for Windows, bash for Linux), creates a playbook, gets human approval, executes on the endpoint, and verifies the fix. Then maps every finding to NIST 800-53 controls via a 3,550-entry CCI crosswalk. POA&M and Risk Acceptance tracking sync to STIG Manager and Jira automatically.

4,700+
STIG findings ingested
47+
LLM-generated playbooks
279
NIST control families
3,550
CCI mappings
LLM-Generated Remediation

The LLM reads DISA fix text, rule descriptions, and check content - then generates real executable commands. PowerShell Set-ItemProperty for Windows registry STIGs. bash sed and systemctl for Linux config STIGs. Not templates. Not snippets. Real commands that actually fix the finding.

Full Remediation Loop

Detect (Evaluate-STIG / OpenSCAP) - Think (LLM analyzes fix text) - Playbook (auto-generated with commands) - Approve (human-in-the-loop) - Execute (HMAC-signed dispatch) - Verify (re-check on endpoint) - Resolve (alert closed, ticket updated, STIG Manager synced). Windows and Linux.

NIST 800-53 Crosswalk

Every STIG finding maps to NIST 800-53r5 controls via a 3,550-entry CCI crosswalk covering 279 control families. POA&M entries and Risk Acceptances sync to STIG Manager and Jira automatically. Pull a compliance report by control family in 60 seconds.

Evaluate-STIG (Windows) - OpenSCAP (Linux) - STIG Manager - Jira - NIST SP 800-53r5 - DISA CCI Reference

Built for the buyers who actually have to defend networks

One platform. Four enclaves.

Each federal buyer has a different security boundary. ATLAS adapts to all of them - without sending your data anywhere it shouldn't go.

🛡️
Department of War

Classified and unclassified networks

ACAS, STIG Manager, and STIG Viewer integration out of the box. CAC/PIV auth. Air-gap packages for classified enclaves. Process-isolated LLM that meets the bar your A&O review will set.

🏛️
Federal Civilian

FISMA, FedRAMP, continuous monitoring

Continuous ATO support. POA&M tracking. Audit-ready reports in 60 seconds. The compliance officer's audit trail is the SOC analyst's incident timeline - same data, different views.

🔍
Intelligence Community

Sensitive compartmented information

SCI enclaves need AI that cannot leak. WebGateway strips hostnames, IPs, FQDNs, and DoW naming conventions. The model sees your question - never your network.

Critical Infrastructure

Energy, finance, healthcare, water

NERC CIP, HIPAA, PCI-DSS. Operational technology environments that can't risk a cloud dependency. ATLAS runs on what you have.

Frequently Asked Questions

The questions your A&O reviewer will ask.

Deployment, security, compliance, procurement. Here are the answers up front.

⚙️

Deployment & Architecture

What hardware do I need for ATLAS?+
ATLAS runs on a dedicated server with a GPU for LLM inference. The hub software stack (FastAPI, PostgreSQL 16, Redis, Ollama) runs on a single RHEL 10 server with FIPS 140-3 enabled. Agent endpoints are lightweight: Windows agent is a ~19MB NSIS installer, Linux agent is a ~17KB shell script. Both run as background services with minimal resource footprint.
What about classified enclaves with no GPU?+
ARES is the classified companion to ATLAS. It runs on a standard VM - no GPU required, no special hardware. BitNet 1.58-bit CPU-only inference: 1.2GB model, 1.5GB RAM, 30+ tokens/second on 8 x86 cores. You spin up a VM on whatever server hardware you already have in the enclave. No GPU procurement, no supply chain wait, no dedicated hardware budget.
How long does deployment take?+
Hub installs in ~20 minutes. Agents deploy silently via GPO, SCCM, or MDM - no reboot required. No Windows server needed for the hub, it runs on Linux only.
What operating system does ATLAS require?+
RHEL 10 with FIPS 140-3 enabled. FIPS is enabled on a clean install before any other software is installed. ATLAS and ARES are designed to run in FIPS mode - it is a requirement, not an option.
What endpoints does ATLAS support?+
Windows 10/11, Windows Server 2019+, and Linux. Agents are lightweight: less than 50MB RAM, less than 1% CPU at idle. Silent install via GPO, SCCM, or MDM.
Is ATLAS hardware-agnostic?+
Yes. No proprietary appliance. ATLAS runs on COTS ruggedized servers (Mercury, Crystal Group, Core Systems, Trenton, HIPER Global) or standard Dell/HPE/IBM rack gear. Navy CANES/TACLAN/ADNS hardware works. ARES runs on any VM - whatever your enclave already has.
Does ATLAS require internet access?+
ATLAS unclassified hubs use the WebGateway for external research - CVE databases, vendor patches, KB articles, troubleshooting steps. Every outbound query passes through a separate sanitization process that strips hostnames, IPs, MAC addresses, FQDNs, and your organization's naming conventions before anything reaches the internet. The LLM itself has no outbound network access. It asks the WebGateway, the WebGateway sanitizes, the WebGateway fetches. The LLM never touches the internet directly.

On classified enclaves, the WebGateway is disabled. All research and updates are delivered via signed air-gap packages on DVD or one-way USB. Zero network contact across the boundary.
Can ATLAS run on SIPR/JWICS/classified enclaves?+
Yes. ATLAS Classified + ARES provides the same STIG automation, remediation loop, and compliance capabilities on classified networks. CPU-only LLM via BitNet, no external dependencies, no internet, signed air-gap delivery. ARES runs on a VM - no GPU, no special hardware.
🛡️

Security & Compliance

How does the LLM stay air-gapped?+
The LLM runs in a process with no outbound network access - no HTTP client, no DNS resolution for external hosts, firewall-blocked from the internet. A separate WebGateway process is the sole communication path between the LLM and the internet. It sanitizes every query, fetches the result, and returns it to the LLM. The LLM cannot bypass, jailbreak, or reason around a network boundary it physically cannot reach.
What gets sanitized?+
Hostnames (including your org's custom naming prefixes, configured at install), IP addresses, MAC addresses, FQDNs with internal domains (.mil, .gov, .local, .internal, .corp), and any infrastructure identifiers that reveal network topology. CVE numbers pass through unmodified - the LLM can query NVD and CISA KEV without leaking internal asset names.
What happens to my data?+
Everything stays on your network. No telemetry, no phone-home, no cloud APIs. Agent data stays in your PostgreSQL database on your hub. The LLM sees real hostnames and IPs internally - your admins need real data in tickets and dashboards to do their jobs. Only outbound web queries are anonymized.
Is ATLAS FIPS-compliant?+
Yes. RHEL 10 with FIPS 140-3 enabled is the deployment target. FIPS is enabled on a clean install before any ATLAS components are installed. The entire stack - OS, database, LLM runtime, agents - runs in FIPS mode.
Has ATLAS been through an A&O review?+
The architecture is designed to meet A&O requirements: process isolation, HMAC-SHA256 signed commands, full audit trail, human-in-the-loop approval gates, CAC/PIV auth, mTLS, service user isolation (hub runs as a dedicated user with no sudo and no shell). We work with your AO during pilot deployment.
What compliance frameworks does ATLAS support?+
STIG scanning (108 STIGs via Evaluate-STIG on Windows, OpenSCAP on Linux), NIST 800-53r5 crosswalk (39 controls, 3,550 CCI mappings), CISA KEV pipeline (6-hour sync), POA&M and Risk Acceptance tracking with STIG Manager and Jira sync. PQC readiness scanning with CNSA 2.0 deadline tracking (January 2027). Insider threat detection: 32 CFR 117, DoDI 5205.16, EO 13587.
What about insider threat detection?+
UAM module with 24 CDSE/MITRE indicators across 30+ Windows event types and Linux auth/audit logs. Behavioral baselining (30-day rolling, statistical profiles), per-user risk scoring (0-100, 5 levels, daily recalculation), investigation case management, session reconstruction, DCSA audit-ready reporting. ISSO-only dashboard access. Fully air-gap-compatible - no cloud, no external dependencies.
What about per-agent trust levels?+
Every agent has a trust level (read-only, write, admin). The hub enforces it. The agent also enforces it locally - defense-in-depth. Self-agents (on the hub box) are locked to read-only and cannot be elevated. Every command is HMAC-SHA256 signed. Unsigned or tampered commands are rejected before execution.
💰

Procurement

How do I buy ATLAS?+
Sandbox is free - request one on the homepage. Production deployments are scoped per enclave size and classification level. Contact us for a quote.
Is ATLAS on any contract vehicles?+
SBIR Direct to Phase II submitted (OSD, ~$1.64M, 12-month period of performance). Microsoft AI Cloud Partner - Commercial Marketplace. GSA schedule in progress. We can also work through your existing prime contractors.
What's the pilot process?+
Tell us your classification level and your enclave size. We set up a matching sandbox with the full admin console and sample data. If it fits, we scope a pilot deployment on your network with your endpoints.
Who is ATLAS Tek?+
Veteran-owned small business in Louisiana. Founded by Tony Moore, 30 years of federal IT experience. 22-claim provisional patent filed with the USPTO. SAM.gov active, SBA.gov approved, CAGE code assigned, DUNS registered. Microsoft AI Cloud Partner.
⚑️

Technical

What integrations does ATLAS support?+
13 integration adapters: NAC: Forescout CounterACT, Cisco ISE, Aruba ClearPass. ITSM: ServiceNow, Jira. SIEM: Splunk, Splunk HEC, Elastic. EDR: Microsoft Defender for Endpoint, CrowdStrike Falcon. RMF: eMASS. Cloud: Zscaler ZIA. STIG: STIG Manager. New integrations can be developed on request.
Can I use my own LLM?+
ATLAS uses Ollama for local inference. Any Ollama-compatible model works - you choose the model that fits your hardware, classification level, and mission. The LLM never has outbound access regardless of which model you choose. ARES uses BitNet 1.58-bit for CPU-only classified enclaves.
How does the console chat work?+
The ATLAS Console is a read-only research chat built into the admin console. 20 read-only tools let the LLM query your hub's APIs for real-time data - agent status, alerts, tickets, playbooks, compliance, STIG scans, PQC assets, UAM indicators. GET-only enforcement, hardcoded tool registry, rate-limited (5 tool calls per message), audit-logged per admin. The LLM can propose actions (draft a ticket, draft a playbook) but cannot execute, approve, or modify anything. Propose, don't execute.
How does the air-gap package system work?+
The unclassified ATLAS hub curates all available patches, STIG updates, threat intelligence, and knowledge base content into a cryptographically signed package. The package is transferred to the classified enclave via approved cross-domain mechanisms (DVD or one-way USB). The classified-side hub determines what to apply based on local inventory. No classified data ever exists on the unclassified side. Multi-disk, numbered, RSA-SHA384 signed, verified before ingest.

If you can't put it in the cloud,
you need ATLAS.

Tell us your classification level and your enclave size. We'll set up a sandbox that matches.

EIN 41-5149481 · DUNS 144981302 · SAM.gov Active · SBA.gov Approved · Louisiana, USA · Patent Pending