Privacy & data

Public disclosure Invited testing Updated September 28, 2026

What Atlas knows about you, and what it can't

In plain language: what Atlas does with your information today, what it's built to be unable to do, and the one place where that is still a promise Layer9i keeps rather than something it can't do.

In one sentence

Atlas gives you an online identity that you hold yourself, not a company, and it's built so that Layer9i can't answer "where has this person been?", even if ordered to.

01

What Atlas is

Atlas is a way to prove who you are online without a company, including Layer9i, keeping a permanent file on you.

Today, most services know an account, not you. Change your phone, switch carriers or lose access to one company, and you start again from nothing. Atlas starts from something only you hold, a recovery phrase, not a device or a company account. So losing a laptop or changing carriers doesn't make you a stranger to the services that already know you.

Atlas doesn't replace your internet provider, and it doesn't watch, filter or block what you do online. That's deliberate, and section 3 explains why. Services that want to accept Atlas are approved one at a time; it isn't open for anyone to plug into.

02

What works today

Atlas is in invited testing, not open to the public yet. This is what exists and has been tested from start to finish:

An account only you hold

It comes from a recovery phrase you write down when you sign up, not from any one device. Losing a device doesn't change who you are to the services that know you.

A different ID for each service

Each service that signs you in with Atlas gets its own ID for you, never one shared ID, so services can't match you up. Today that's Layer9i's own test service; real services come next.

Proof without asking Layer9i

Layer9i's test service checks that you are who you say using a key Layer9i publishes openly. It never has to contact Layer9i or share a secret with it to do it.

Apps on four platforms

Mac, iPhone, Android and Windows, used by invited testers. They carry your account and, if you choose, the city sites see you connecting from.

Your choices locked on your devices

Since September 27, 2026, the apps lock your choices on your own device before saving them. Layer9i stores only the locked copy and can't see which sites they name or where they send them.

Choose where you appear from, if you want

You can choose the city sites see you connecting from. It's off until you turn it on, and outside services confirm it's working.

Recovery only you can do

The key you get when you sign up is the only way back into your account or to reset it. Layer9i never has a copy.

Your account isn't tied to your traffic

The servers your connection passes through let you in with a pass from your account, and keep no record of which account used which internet address. This is how they run today, not just a plan.

Not built yet: public sign-up (joining is by invitation), a second service run by someone other than Layer9i, and the last step described in section 5.

03

What's built in

These are built into how Atlas works, not lines in a privacy policy that could be quietly changed. Each one costs Layer9i something, in exchange for not being able to be forced to hand over more.

Nobody else holds your recovery

Your key is created on your device and held only by you. Layer9i keeps no copy and has no back door. The cost: if you lose it, Layer9i can't get your account back for you.

Who you are and where you connect from are kept apart

Nothing Layer9i keeps links you directly to an internet address you've used. To connect, your device shows a valid pass. Layer9i doesn't need to know, or ask, who's holding it.

Anyone can check, no secrets needed

Everything Atlas confirms about you is signed, and can be checked against a key Layer9i publishes. A service checks it directly instead of taking Layer9i's word for it.

Services are approved one at a time

Atlas isn't open for any service to plug into without Layer9i knowing. Each one is approved individually, so its setup is checked in advance rather than trusted blindly.

Services can't compare notes

The ID one service has for you can't be matched to the ID another service has, even if they share their records. This has been built in from the very first service, not added later.

Choices Layer9i can't read

Your choices open with your key or a separate recovery code you write down, never with anything Layer9i holds. The cost: lose both, and nobody, including Layer9i, can get them back.

No watching where you go

Atlas doesn't look at, record, filter or flag the sites you visit. Deciding what's allowed online is your internet provider's job. Atlas's job is proving who you are, and it doesn't take on the first to make the second look safer.

04

What Layer9i could and couldn't hand over

This is the real test of the promises above: what could Layer9i hand over if a court ordered it to give up everything it has? The honest answer is a mix. A few things are kept because Atlas can't work without them. Much more simply isn't kept, because nothing in Atlas writes it down.

QuestionCould Layer9i answer it?
Does an email address have an Atlas account, and when was it created?Yes
Which devices are on an account, and each device's current internet address?Yes, but only what's current. No history beyond a short period.
Which city has an account currently chosen to appear from?Yes, the current choice only, not past choices.
How many connection passes did an account ask for in a period?Yes, a count only, not which passes.
Who was using a given internet address at some point in the past?No. Nothing is kept beyond a short period.
Which sites do someone's choices name, and where do they send them?No, for choices locked by the current apps. Layer9i only has a locked copy it can't open. Choices saved by apps from before September 27, 2026 stay readable until that person updates.
Which sites did someone visit?No. Layer9i keeps no record of the sites anyone's traffic reaches.
Who does an ID belong to, using only what a service holds?No. It can't be traced back without Atlas's own signing keys.
Can Atlas switch off a device or an account on request?Yes. This exists and is used.

Layer9i can't make an exception to any "No" above just for court orders. Keeping a record for some people means keeping it for everyone. There's no halfway version of not keeping a record.

05

The one promise that isn't yet a guarantee

One thing above sits in between. No service, alone or by comparing notes with another, can work out who you are from the ID it holds. But Layer9i's own sign-in system could, today, work out which person an ID belongs to, because it's the system that created it. So "is this ID person X?" is a question Layer9i could technically be asked.

Until that changes, here is the rule Layer9i follows: once its system hands out a pass, it keeps nothing about it except a running count. No copy, no fingerprint of it, nothing that links it back to you. That makes the question impossible to answer in practice today, but it rests on a rule about what Layer9i chooses not to keep, not on the maths.

The last piece of work changes that. It uses a technique called blind signatures, and an outside cryptography expert will review it before it ships. After that, Atlas won't be able to work out the answer at all, rather than just promising not to look. Atlas stays invitation-only until it ships, and this page will be updated when it does.

06

Point out what's wrong

This page describes Atlas as it's being tested today, not a finished product. If anything here looks wrong, missing or overstated, please say so using the button below. That kind of review is exactly what Layer9i is asking for.

Review this page

Send feedback Email a review