Privacy Policy
Effective Date: 1 November 2025
Last Updated: 9 September 2026
Introduction
Athena Consulting Group, LLC ("Athena," "we," "our," "us") operates the Athena CMMC Omniverse™ available at https://auditor-athena.com ("Service").
This Privacy Policy explains how we collect, use, store, share, and protect personal information, including data accessed through Google APIs.
If you have any questions, contact us at: info@athenaconsultinggroup.com
1. Information We Collect
1.1 Information You Provide
- Account registration information (name, email, organization)
- Uploaded assessment data (policies, evidence, gap analysis details)
- User roles, workflows, and preferences
1.2 Information Collected Automatically
- IP addresses, browser type, and device metadata
- Activity logs and audit trails
- Technical performance metrics
- Authentication-related metadata
1.3 Information Received From Google APIs (OAuth)
If you sign in with Google, we receive:
- Basic profile information (name, email, profile image)
- Organization domain (Google Workspace users)
Separately, and only if you choose to connect Google Drive as an evidence source, we request the drive.file scope. That scope is limited to the specific files you select or that Athena creates; it does not give Athena access to your wider Drive. You can disconnect the integration at any time, which revokes our access to those files going forward.
We do NOT request or access:
- Gmail message content
- Google Drive files you have not selected or that Athena did not create
- Calendar events
- Contacts
- Sensitive or restricted Google Workspace administrative data
2. How We Use Google User Data
Your Google user data is used solely to:
- Authenticate your identity
- Create and maintain your account
- Associate you with your organizational workspace
- Provide core CMMC workflow functionality
We do NOT:
- Sell Google user data
- Share it with unauthorized third parties
- Use it for advertising
- Use Google user data to train AI or machine-learning models
- Use it for any unapproved purpose
This complies with Google's User Data Policy and AI/ML training restrictions.
2.1 How AI Processing Works
Athena sends the documents and assessment text you provide to hosted AI models through the platform's AI gateway in order to draft your artifacts. That processing happens inside your tenant's workflow. We do not use your documents, prompts, or reviewer corrections to train shared or third-party foundation models. Reviewer corrections are used to improve the instructions Athena runs against your own tenant's data and to measure accuracy internally.
3. Data Storage and Security
We employ industry-standard security controls aligned with the U.S. Department of Defense cybersecurity requirements.
3.1 Technical Protections
- Encryption in transit (TLS 1.2+)
- Encryption at rest
- Role-based access control (RBAC)
- Multi-factor authentication
- Continuous monitoring
- Audit logging
3.2 Framework Alignment
Our platform aligns with:
- NIST SP 800-171 Rev 2
- CMMC Level 2 requirements
- DFARS 252.204-7012 cybersecurity principles
3.3 Data Segregation
Customer data is logically separated by tenant and isolated from other customer environments.
4. Data Retention
We retain information only as long as necessary for:
- Providing the Service
- Maintaining account functionality
- Fulfilling legal or contractual obligations
Current retention periods:
- Account and profile data → while your account is active
- Assessment content, evidence and generated artifacts → while your account is active, and deleted within 30 days of account closure or a deletion request unless a longer period is required by law or your contract
- Internal scheduled-job and outbound HTTP logs → pruned automatically after 7 days
- Compliance audit trails (who changed what, and when) → retained for the life of the account, because they are part of your assessment record
You may request deletion at any time (see Section 8).
5. When We Share Information
We share personal data only with the service providers we actually use to operate Athena:
- Application hosting, database, authentication, file storage and serverless functions — our managed cloud platform provider, running on Amazon Web Services in United States regions
- AI model processing — hosted models reached through the platform's AI gateway (currently including Google Gemini models) for drafting and analysing your artifacts
- Payments — Stripe (card data goes to Stripe, never to Athena)
- Outbound notification and alert email — the platform's email/Gmail delivery connector
- Google Drive — only if you connect it as an evidence source, and only for files you select
- Public-website delivery and crawler rendering — our CDN and prerendering provider, which handle only public marketing pages, never signed-in customer data
- AWS Wickr — where a customer chooses the regulated-data configuration, Wickr runs inside the customer's own AWS boundary and the customer remains the data owner
All such providers operate under confidentiality and security requirements. Athena Consulting Group holds no SOC 2 report or ISO certificate of its own, and is not FedRAMP authorized; see the Security page for the full assurance posture.
We never:
- Sell personal information
- Share data for marketing purposes
- Transfer data to unauthorized third parties
6. Children's Privacy
Our Service is intended for users aged 18 and older. We do not knowingly collect information from children.
8. Data Deletion Requests
You may request account deletion and associated data removal at any time.
We will:
- Remove your account
- Delete your content, assessments, and evidence
- Purge personal identifiers from logs
- Confirm deletion within thirty (30) days
Submit requests to: info@athenaconsultinggroup.com
9. Global Privacy Compliance
We comply with generally recognized privacy principles, including:
- Data minimization
- Lawful basis for processing
- User transparency
- Right to deletion
- No sale of personal information
These principles support GDPR, CCPA, and other global standards.
10. Changes to This Policy