Privacy Policy

    Effective Date: 1 November 2025

    Last Updated: 9 September 2026

    Introduction

    Athena Consulting Group, LLC ("Athena," "we," "our," "us") operates the Athena CMMC Omniverse™ available at https://auditor-athena.com ("Service").

    This Privacy Policy explains how we collect, use, store, share, and protect personal information, including data accessed through Google APIs.

    If you have any questions, contact us at: info@athenaconsultinggroup.com

    1. Information We Collect

    1.1 Information You Provide

    • Account registration information (name, email, organization)
    • Uploaded assessment data (policies, evidence, gap analysis details)
    • User roles, workflows, and preferences

    1.2 Information Collected Automatically

    • IP addresses, browser type, and device metadata
    • Activity logs and audit trails
    • Technical performance metrics
    • Authentication-related metadata

    1.3 Information Received From Google APIs (OAuth)

    If you sign in with Google, we receive:

    • Basic profile information (name, email, profile image)
    • Organization domain (Google Workspace users)

    Separately, and only if you choose to connect Google Drive as an evidence source, we request the drive.file scope. That scope is limited to the specific files you select or that Athena creates; it does not give Athena access to your wider Drive. You can disconnect the integration at any time, which revokes our access to those files going forward.

    We do NOT request or access:

    • Gmail message content
    • Google Drive files you have not selected or that Athena did not create
    • Calendar events
    • Contacts
    • Sensitive or restricted Google Workspace administrative data

    2. How We Use Google User Data

    Your Google user data is used solely to:

    • Authenticate your identity
    • Create and maintain your account
    • Associate you with your organizational workspace
    • Provide core CMMC workflow functionality

    We do NOT:

    • Sell Google user data
    • Share it with unauthorized third parties
    • Use it for advertising
    • Use Google user data to train AI or machine-learning models
    • Use it for any unapproved purpose

    This complies with Google's User Data Policy and AI/ML training restrictions.

    2.1 How AI Processing Works

    Athena sends the documents and assessment text you provide to hosted AI models through the platform's AI gateway in order to draft your artifacts. That processing happens inside your tenant's workflow. We do not use your documents, prompts, or reviewer corrections to train shared or third-party foundation models. Reviewer corrections are used to improve the instructions Athena runs against your own tenant's data and to measure accuracy internally.

    3. Data Storage and Security

    We employ industry-standard security controls aligned with the U.S. Department of Defense cybersecurity requirements.

    3.1 Technical Protections

    • Encryption in transit (TLS 1.2+)
    • Encryption at rest
    • Role-based access control (RBAC)
    • Multi-factor authentication
    • Continuous monitoring
    • Audit logging

    3.2 Framework Alignment

    Our platform aligns with:

    • NIST SP 800-171 Rev 2
    • CMMC Level 2 requirements
    • DFARS 252.204-7012 cybersecurity principles

    3.3 Data Segregation

    Customer data is logically separated by tenant and isolated from other customer environments.

    4. Data Retention

    We retain information only as long as necessary for:

    • Providing the Service
    • Maintaining account functionality
    • Fulfilling legal or contractual obligations

    Current retention periods:

    • Account and profile data → while your account is active
    • Assessment content, evidence and generated artifacts → while your account is active, and deleted within 30 days of account closure or a deletion request unless a longer period is required by law or your contract
    • Internal scheduled-job and outbound HTTP logs → pruned automatically after 7 days
    • Compliance audit trails (who changed what, and when) → retained for the life of the account, because they are part of your assessment record

    You may request deletion at any time (see Section 8).

    5. When We Share Information

    We share personal data only with the service providers we actually use to operate Athena:

    • Application hosting, database, authentication, file storage and serverless functions — our managed cloud platform provider, running on Amazon Web Services in United States regions
    • AI model processing — hosted models reached through the platform's AI gateway (currently including Google Gemini models) for drafting and analysing your artifacts
    • Payments — Stripe (card data goes to Stripe, never to Athena)
    • Outbound notification and alert email — the platform's email/Gmail delivery connector
    • Google Drive — only if you connect it as an evidence source, and only for files you select
    • Public-website delivery and crawler rendering — our CDN and prerendering provider, which handle only public marketing pages, never signed-in customer data
    • AWS Wickr — where a customer chooses the regulated-data configuration, Wickr runs inside the customer's own AWS boundary and the customer remains the data owner

    All such providers operate under confidentiality and security requirements. Athena Consulting Group holds no SOC 2 report or ISO certificate of its own, and is not FedRAMP authorized; see the Security page for the full assurance posture.

    We never:

    • Sell personal information
    • Share data for marketing purposes
    • Transfer data to unauthorized third parties

    6. Children's Privacy

    Our Service is intended for users aged 18 and older. We do not knowingly collect information from children.

    7. Your Rights & Choices

    You may have the right to:

    • Access your personal data
    • Request correction
    • Request deletion
    • Restrict certain processing
    • Export your data
    • Revoke Google OAuth permissions

    Revoke OAuth access at:

    https://myaccount.google.com/permissions

    You may also contact us directly at: info@athenaconsultinggroup.com

    8. Data Deletion Requests

    You may request account deletion and associated data removal at any time.

    We will:

    • Remove your account
    • Delete your content, assessments, and evidence
    • Purge personal identifiers from logs
    • Confirm deletion within thirty (30) days

    Submit requests to: info@athenaconsultinggroup.com

    9. Global Privacy Compliance

    We comply with generally recognized privacy principles, including:

    • Data minimization
    • Lawful basis for processing
    • User transparency
    • Right to deletion
    • No sale of personal information

    These principles support GDPR, CCPA, and other global standards.

    10. Changes to This Policy

    We may update this Privacy Policy as needed. Any changes will be posted at:

    https://auditor-athena.com/privacy-policy

    Continued use of the Service constitutes acceptance of updated terms.

    11. Contact Information

    Athena Consulting Group, LLC

    5895 Core Rd, Suite 407

    North Charleston, SC 29406

    Email: info@athenaconsultinggroup.com