Skip to content
Atlas · Private beta

The secure control plane for device operations.

Atlas gives every connected device a cryptographic identity and gives your team one place to provision, secure, monitor, and update the fleet — from a single prototype to millions in the field.

Capabilities

Everything a fleet needs, in one platform.

Eight capabilities that work as one system — each rooted in the same identity and audit model.

Device provisioning

Bring a device online through explicit lifecycle states — pending, active, disabled, decommissioned. Just-in-time enrollment lets devices register the first time they connect, against a CA you trust.

PKI & certificate authorities

Run an internal CA or register and cryptographically verify your own. Atlas holds the trust chain devices enroll against, so identity is rooted in cryptography rather than configuration.

Certificate lifecycle

Issue, sign, and revoke device certificates. Atlas-managed CSR signing or bring-your-own — either way, every credential has a clear origin, owner, and expiry.

Fleet management

A single inventory for the whole fleet, with strict multi-tenant isolation. Approve, disable, and decommission devices with role-gated actions and full history.

Telemetry

Ingest structured telemetry over MQTT and TLS, streamed through the broker into Atlas. See fleet health as it happens and keep the signal that matters.

Logging & diagnostics

Collect device logs alongside telemetry so you can diagnose a device in the field without a physical connection to it.

Security

mTLS between devices and the platform, least-privilege roles on every privileged action, and devices treated as untrusted clients by default. Security is the product, not a setting.

Observability

Every provisioning, certificate, and lifecycle event lands in a tamper-evident audit trail — an operational record and a compliance artifact in one.

Architecture

A clear, secure path from device to dashboard.

Devices are untrusted at the edge and stay authenticated end to end. Data flows over TLS through the broker into Atlas, where it becomes fleet state you can act on.

  1. 01DeviceUntrusted client · mTLS identity
  2. 02EMQX brokerMQTT 5 over TLS
  3. 03Atlas ingestionAuth · validation · routing
  4. 04PostgreSQLFleet state · time-series telemetry
  5. 05Console & APIOperate · observe · audit
Security first

Trust is earned by devices, never assumed.

Cryptographic identity

Certificate-based device identity with mTLS on the wire. No client-supplied identity claim is ever trusted.

Least privilege

Owner, admin, and member roles gate every privileged action across every organization.

Tenant isolation

Devices, certificates, and telemetry are scoped to an organization and validated on every request.

Auditable by default

A tamper-evident trail records provisioning, certificate, and lifecycle events for operations and compliance.

Put Atlas to work on your fleet.

Atlas is in private beta with a small group of design partners. If you operate connected hardware, we'd like to talk.