Security & Privacy

    How Athena treats your evidence.

    This page is maintained by Athena Consulting Group to answer common security and privacy questions about the Athena platform. It describes enabled controls and current operational practices; it is not a third-party certification or attestation.

    Need a security questionnaire, a DPA, or a written response on a control not covered here? Email Doug at ACG.

    Current practices

    Customer data is not used to train models

    Athena uses your evidence to draft your artifacts inside your tenant. ACG does not use customer documents, prompts, or reviewer corrections to train shared or third-party foundation models. Reviewer corrections improve only the prompts that run against your tenant's data.

    Tenant isolation via row-level security

    Customer-facing tables enforce row-level security policies in Postgres scoped to the authenticated user. Reads and writes are filtered at the database, not the application layer, so a request from one customer cannot read or modify another customer's rows.

    Encryption in transit and at rest

    All traffic to Athena uses TLS 1.3. Database and storage encryption at rest is provided by the underlying managed cloud platform. Service-role credentials remain inside edge functions and are never exposed to the browser.

    Cryptographic artifact provenance

    Defensible artifacts (for example SAR drafts, POA&M exports, and assessor packages) are sha256-snapshotted at creation. Snapshots are immutable and deduped, and anything shared with an external assessor references the snapshot — not a mutable live record.

    US-based infrastructure

    Athena runs on US AWS regions through its managed cloud platform. If your assessment requires additional residency, isolation, or deployment controls, contact ACG to scope alternatives.

    Access control and authentication

    Sign-in is handled by the managed cloud platform's auth service. Application roles are stored in a dedicated table and checked through a security-definer function, not on user-editable profile records.

    Third-party assurance & FedRAMP posture

    Which certifications exist, who actually holds them, and where regulated CUI lives. Reviewed 9 September 2026.

    Held by: SaaS delivery platform provider

    ISO 9001 and ISO 27001 sit with the platform provider

    Athena is delivered as a SaaS application on a managed cloud platform whose provider states that it maintains ISO 9001 (quality management) and ISO 27001 (information security management) certification. Those certificates are held and published by that provider, and are available from the provider on request. They are not certificates of Athena Consulting Group or of the Athena application.

    Held by: Athena Consulting Group

    Athena Consulting Group holds no SOC 2 report of its own

    Athena Consulting Group has not completed a SOC 2 Type I or Type II examination and does not hold an ISO certificate in its own name. Where a solicitation asks for SOC 2, we answer with the platform provider attestations above, the practices published on this page, and a direct written response to the questionnaire.

    Held by: AWS Wickr

    The FedRAMP-authorized component is AWS Wickr

    For customers who must keep regulated CUI inside a FedRAMP-authorized service, our solution uses AWS Wickr as that service. AWS holds the FedRAMP authorization for Wickr; the customer operates it inside their own AWS boundary and remains the data owner. Athena integrates with that boundary to support the CMMC and NIST SP 800-171 evidence workflow around it.

    Held by: Athena Consulting Group

    Athena is not FedRAMP authorized and does not inherit authorization

    Athena Consulting Group has no FedRAMP Marketplace listing and makes no claim of FedRAMP authorization, equivalency, or inheritance. Athena maps to FedRAMP Moderate controls for assessment purposes only. Regulated CUI is never required to enter Athena: it stays in the customer's authorized AWS Wickr boundary, and only sanitized assessment metadata crosses into Athena.

    Held by: CMMC Accreditation Body-listed C3PAO

    Certification is issued by a C3PAO, never by Athena

    Athena is a CMMC readiness, assessment-operations, evidence and assessor-preparation platform. It does not issue or grant CMMC certification. Certification is determined by a CMMC Accreditation Body-listed C3PAO under 32 CFR Part 170.

    Shared responsibility

    Security of Athena is split across three actors. Knowing which commitments live where helps avoid gaps.

    Underlying cloud platform

    • Physical data center security and US region availability
    • Database, storage, and network primitives with encryption at rest
    • Authentication service used for sign-in
    • Edge runtime that executes server-side functions

    ACG (Athena platform owner)

    • Application code, row-level security policies, and edge function logic
    • Cryptographic snapshotting of defensible artifacts
    • Practices stated on this page; vendor selection and configuration
    • Responding to security questionnaires and data processing addendums (DPAs) via Doug.Majewski@athenaconsultinggroup.com

    Customer (your team)

    • Provisioning least-privilege accounts and removing access on offboarding
    • Classifying which documents are appropriate to upload to Athena
    • Reviewing AI-drafted artifacts before treating them as final
    • Notifying ACG of suspected security issues or account compromise

    Security contact & reporting

    General security inquiries

    Questionnaires, DPAs, audit-letter requests, or anything else procurement-related.

    Vulnerability reporting

    If you believe you've found a security issue in Athena, please report it in good faith. ACG will acknowledge receipt and follow up directly.

    This page describes Athena platform practices maintained by Athena Consulting Group. It is not a third-party audit report, certification, or legal contract, and individual customer agreements may include additional or different terms.

    See also our Privacy Policy and Terms of Service.