Atari VPN Atari

Security

Connection and data protection

This page describes verifiable technical facts, the data required by the service, and limitations to understand before connecting.

Principle: collect what is required

Atari VPN separates account, subscription, and payment data. Public statements are limited to what the current code and configuration can demonstrate; stronger no-logs or storage claims require a dedicated infrastructure audit.

Encrypted VPN connection

A connection creates an encrypted tunnel between a compatible client and the VPN server. The installed app receives the selected profile through the user's personal subscription link.

Tunnel protection does not replace security after traffic leaves the VPN server. Account safety, website HTTPS, and the security of the device remain important.

  • Do not share a subscription link.
  • Use a current client from the instructions channel.
  • Protect and update the device.

Account data

The website requires an email for registration, sign-in, and access recovery. The password is not stored as plain text; the database retains a cryptographic result of password processing.

The web session is also checked with a protected token. When Telegram is linked voluntarily, the account is associated with the corresponding Telegram ID.

  • Account email
  • Password hash
  • Protected web session
  • Telegram ID only after linking

Payment data

Atari VPN does not store the full bank card number or CVC. The card operation is processed by the payment provider.

When the user saves a payment method, the service stores an encrypted provider identifier, an HMAC fingerprint, the type and display title, and the last four digits. This is not the same as storing only one hash and cannot reconstruct the full card number.

  • No full card number
  • No CVC
  • Saving a method is the user's choice

Operational logs and diagnostics

The website and infrastructure may require technical events to diagnose errors, monitor availability, and prevent abuse. This should not be described as the absence of every type of log.

A separate claim about not retaining network activity history is published only after auditing VPN nodes, DNS, the control panel, containers, and reverse proxy. Until then Atari VPN does not use an absolute no-logs statement.

  • Do not use logs for advertising profiles
  • Minimise operational log fields
  • Review retention after infrastructure changes

Protection of stored values

Sensitive application values are protected according to purpose: passwords are hashed and the payment provider identifier is encrypted with a separate key. This is not a claim that every database record is encrypted.

A statement about full database and backup encryption requires evidence of encrypted storage, protected backups, separate keys, and a tested restoration process.

  • Keys must not be stored in database dumps
  • Backup restoration is tested separately
  • Access to production secrets is restricted

What a VPN cannot guarantee

A VPN does not make a person completely anonymous. Websites may recognise a signed-in account, browsers may store cookies, and the device itself can contain unsafe or malicious software.

The service also cannot guarantee one speed, availability of every external website, or protection from actions performed after signing into a third-party account.

  • Check HTTPS
  • Never share passwords or one-time codes
  • Use unique passwords

Report a security issue

If you notice suspicious activity, an access error, or a possibly exposed subscription link, contact AtariVPNBot. Support can help revoke access or check the account.

Do not send a password, CVC, full card number, or exposed subscription secret through Telegram. A device description, event time, and safe screenshot are normally enough for initial diagnostics.