Access and sessions
Atlas combines domain authorization, server-side sessions and optional SSO with passkeys, one-time codes and SAML applications. Argos authenticates authorized local operators through PAM and requires TOTP from WAN and configured zones; permissions and MFA requirements are checked on subsequent requests too. Partner access through Citadel is an explicit administrative grant, revocable by disconnecting the appliance.
An explicit inspection boundary
Argos does not decrypt TLS. It analyzes available metadata, TLS/QUIC JA4 client fingerprints and application signals; traffic with insufficient signals remains unclassified. When the inline engine is unavailable the queue allows traffic through. Passive observation does not issue blocking verdicts. Coverage depends on selected zones, protocols and loaded signatures.
Service data and metadata
Atlas stores sessions on the server and retains user credentials for calendar and contact synchronization for the session lifetime. Argos collects threat-detection events and traffic observations, storing configurations locally. Access, retention and backups require appropriate configuration and protection.
Updates and disclosure
Software is distributed through installation packages. Atlas manages system updates and maintenance windows. Support duration, SLAs and the official vulnerability-reporting channel are not yet published: do not send vulnerabilities through the commercial form.