This page is maintained by Athena Consulting Group to answer common security and privacy questions about the Athena platform. It describes enabled controls and current operational practices; it is not a third-party certification or attestation.
Need a security questionnaire, a DPA, or a written response on a control not covered here? Email Doug at ACG.
Athena uses your evidence to draft your artifacts inside your tenant. ACG does not use customer documents, prompts, or reviewer corrections to train shared or third-party foundation models. Reviewer corrections improve only the prompts that run against your tenant's data.
Customer-facing tables enforce row-level security policies in Postgres scoped to the authenticated user. Reads and writes are filtered at the database, not the application layer, so a request from one customer cannot read or modify another customer's rows.
All traffic to Athena uses TLS 1.3. Database and storage encryption at rest is provided by the underlying managed cloud platform. Service-role credentials remain inside edge functions and are never exposed to the browser.
Defensible artifacts (for example SAR drafts, POA&M exports, and assessor packages) are sha256-snapshotted at creation. Snapshots are immutable and deduped, and anything shared with an external assessor references the snapshot — not a mutable live record.
Athena runs on US AWS regions through its managed cloud platform. If your assessment requires additional residency, isolation, or deployment controls, contact ACG to scope alternatives.
Sign-in is handled by the managed cloud platform's auth service. Application roles are stored in a dedicated table and checked through a security-definer function, not on user-editable profile records.
Which certifications exist, who actually holds them, and where regulated CUI lives. Reviewed 9 September 2026.
Athena is delivered as a SaaS application on a managed cloud platform whose provider states that it maintains ISO 9001 (quality management) and ISO 27001 (information security management) certification. Those certificates are held and published by that provider, and are available from the provider on request. They are not certificates of Athena Consulting Group or of the Athena application.
Athena Consulting Group has not completed a SOC 2 Type I or Type II examination and does not hold an ISO certificate in its own name. Where a solicitation asks for SOC 2, we answer with the platform provider attestations above, the practices published on this page, and a direct written response to the questionnaire.
For customers who must keep regulated CUI inside a FedRAMP-authorized service, our solution uses AWS Wickr as that service. AWS holds the FedRAMP authorization for Wickr; the customer operates it inside their own AWS boundary and remains the data owner. Athena integrates with that boundary to support the CMMC and NIST SP 800-171 evidence workflow around it.
Athena Consulting Group has no FedRAMP Marketplace listing and makes no claim of FedRAMP authorization, equivalency, or inheritance. Athena maps to FedRAMP Moderate controls for assessment purposes only. Regulated CUI is never required to enter Athena: it stays in the customer's authorized AWS Wickr boundary, and only sanitized assessment metadata crosses into Athena.
Athena is a CMMC readiness, assessment-operations, evidence and assessor-preparation platform. It does not issue or grant CMMC certification. Certification is determined by a CMMC Accreditation Body-listed C3PAO under 32 CFR Part 170.
Security of Athena is split across three actors. Knowing which commitments live where helps avoid gaps.
Questionnaires, DPAs, audit-letter requests, or anything else procurement-related.
If you believe you've found a security issue in Athena, please report it in good faith. ACG will acknowledge receipt and follow up directly.