Skip to main content
Athena is SOC 2 Type II and HIPAA compliant, and never trains models on customer data. Connected systems are accessed as each individual user, so the source system’s permissions apply to every request. Athena can run in its managed cloud, in your own cloud account (VPC), on-premises, or fully air-gapped.

Is Athena SOC 2 compliant?

Yes. Athena is SOC 2 Type II and HIPAA compliant. Contact team@athenaintel.com to request compliance documentation.

Does Athena train on my data?

No. Athena does not use customer data to train, fine-tune or improve any model, and this is part of the customer contract. Athena’s model providers operate under contractual zero-data-retention agreements: data sent to them for processing is not stored or used for training.

Does Athena store data from my connected systems?

Not permanently. When you connect SharePoint, OneDrive, Google Drive, iManage, Snowflake and similar systems as Live Assets, files and records stay in the source system:
  • Athena fetches content on demand, as the signed-in user.
  • To avoid repeated fetches, file contents are kept in an encrypted, short-lived cache that expires after one hour by default.
  • Athena keeps only the metadata and identifiers needed to find the item again.
Files you upload directly are stored in Athena’s secure storage so they can be converted, searched and reused.

How does Athena handle permissions on connected data?

With a per-user connection, each user connects their own account, usually through OAuth, so Athena acts as that person. Access is checked against the source system every time a Live Asset is opened. If someone loses access to a file in the source system, they lose it in Athena at the same moment. Agents get the same permissions as the person they work for. Some integrations also offer a shared connection, such as a BigQuery service account or an admin-registered SharePoint app. Requests on a shared connection run with that account’s rights, not each user’s, so use per-user connections where individual permissions must apply. Most integrations support per-user sign-in:

Does Athena support SSO and SCIM?

Yes. Athena supports SAML 2.0 and OIDC single sign-on with Microsoft Entra ID, Okta, Google Workspace and any compliant identity provider. Your identity provider’s MFA policies apply to Athena logins. With SCIM, users you deactivate in your identity provider are deactivated in Athena automatically. See Single Sign-On (SSO).

Can Athena be deployed in my own cloud?

Yes. Athena offers four deployment models: The no-training commitment applies in every deployment model. See deployment options.

Can I see and undo what Athena did?

Yes. Every change made by a person or an agent is attributed to whoever made it, and changes can be undone. AOPs are versioned, so you can see who changed a procedure and when, and restore any earlier version. Athena’s answers cite their sources with deep links to the exact passage, page or cell.