Regulated communications and evidence stay inside the authorized secure boundary. Athena Fortify-CMMC runs the assessment workflow on approved metadata, opaque references, responsibilities, status, and sanitized conclusions. Everything below is a surface that either enforces that separation or explains it.
Configure and monitor the separation between the authorized secure boundary (AWS Wickr) and Athena's SaaS. Regulated content never enters Athena; Athena carries sanitized metadata, references, status, and conclusions.
Decide what is actually in scope before you spend money assessing it, then label it so handling rules survive an assessor challenge.
Athena's SaaS is not FedRAMP authorized, and no component's authorization transfers to Athena. These pages state the position precisely so proposals and assessors get the same answer.