This page is maintained by Athena Consulting Group to answer common security and privacy questions about the Athena platform. It describes enabled controls and current operational practices; it is not a third-party certification or attestation.
Need a security questionnaire, a DPA, or a written response on a control not covered here? Email Doug at ACG.
Athena uses your evidence to draft your artifacts inside your tenant. ACG does not use customer documents, prompts, or reviewer corrections to train shared or third-party foundation models. Reviewer corrections improve only the prompts that run against your tenant's data.
Customer-facing tables enforce row-level security policies in Postgres scoped to the authenticated user. Reads and writes are filtered at the database, not the application layer, so a request from one customer cannot read or modify another customer's rows.
All traffic to Athena uses TLS 1.3. Database and storage encryption at rest is provided by the underlying managed cloud platform. Service-role credentials remain inside edge functions and are never exposed to the browser.
Defensible artifacts (for example SAR drafts, POA&M exports, and assessor packages) are sha256-snapshotted at creation. Snapshots are immutable and deduped, and anything shared with an external assessor references the snapshot — not a mutable live record.
Athena runs on US AWS regions through its managed cloud platform. If your assessment requires additional residency, isolation, or deployment controls, contact ACG to scope alternatives.
Sign-in is handled by the managed cloud platform's auth service. Application roles are stored in a dedicated table and checked through a security-definer function, not on user-editable profile records.
Security of Athena is split across three actors. Knowing which commitments live where helps avoid gaps.
Questionnaires, DPAs, audit-letter requests, or anything else procurement-related.
If you believe you've found a security issue in Athena, please report it in good faith. ACG will acknowledge receipt and follow up directly.