Security & Privacy

    How Athena treats your evidence.

    This page is maintained by Athena Consulting Group to answer common security and privacy questions about the Athena platform. It describes enabled controls and current operational practices; it is not a third-party certification or attestation.

    Need a security questionnaire, a DPA, or a written response on a control not covered here? Email Doug at ACG.

    Current practices

    Customer data is not used to train models

    Athena uses your evidence to draft your artifacts inside your tenant. ACG does not use customer documents, prompts, or reviewer corrections to train shared or third-party foundation models. Reviewer corrections improve only the prompts that run against your tenant's data.

    Tenant isolation via row-level security

    Customer-facing tables enforce row-level security policies in Postgres scoped to the authenticated user. Reads and writes are filtered at the database, not the application layer, so a request from one customer cannot read or modify another customer's rows.

    Encryption in transit and at rest

    All traffic to Athena uses TLS 1.3. Database and storage encryption at rest is provided by the underlying managed cloud platform. Service-role credentials remain inside edge functions and are never exposed to the browser.

    Cryptographic artifact provenance

    Defensible artifacts (for example SAR drafts, POA&M exports, and assessor packages) are sha256-snapshotted at creation. Snapshots are immutable and deduped, and anything shared with an external assessor references the snapshot — not a mutable live record.

    US-based infrastructure

    Athena runs on US AWS regions through its managed cloud platform. If your assessment requires additional residency, isolation, or deployment controls, contact ACG to scope alternatives.

    Access control and authentication

    Sign-in is handled by the managed cloud platform's auth service. Application roles are stored in a dedicated table and checked through a security-definer function, not on user-editable profile records.

    Shared responsibility

    Security of Athena is split across three actors. Knowing which commitments live where helps avoid gaps.

    Underlying cloud platform

    • Physical data center security and US region availability
    • Database, storage, and network primitives with encryption at rest
    • Authentication service used for sign-in
    • Edge runtime that executes server-side functions

    ACG (Athena platform owner)

    • Application code, row-level security policies, and edge function logic
    • Cryptographic snapshotting of defensible artifacts
    • Practices stated on this page; vendor selection and configuration
    • Responding to security questionnaires and data processing addendums (DPAs) via Doug.Majewski@athenaconsultinggroup.com

    Customer (your team)

    • Provisioning least-privilege accounts and removing access on offboarding
    • Classifying which documents are appropriate to upload to Athena
    • Reviewing AI-drafted artifacts before treating them as final
    • Notifying ACG of suspected security issues or account compromise

    Security contact & reporting

    General security inquiries

    Questionnaires, DPAs, audit-letter requests, or anything else procurement-related.

    Vulnerability reporting

    If you believe you've found a security issue in Athena, please report it in good faith. ACG will acknowledge receipt and follow up directly.

    This page describes Athena platform practices maintained by Athena Consulting Group. It is not a third-party audit report, certification, or legal contract, and individual customer agreements may include additional or different terms.

    See also our Privacy Policy and Terms of Service.