> ## Documentation Index
> Fetch the complete documentation index at: https://resources.athenaintel.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Athena Security and Data Handling

> How Athena protects your data: SOC 2 Type II and HIPAA, no training on customer data, per-user access to connected systems, SSO and SCIM, and VPC deployment.

Athena is SOC 2 Type II and HIPAA compliant, and never trains models on customer data. Connected systems are accessed as each individual user, so the source system's permissions apply to every request. Athena can run in its managed cloud, in your own cloud account (VPC), on-premises, or fully air-gapped.

## Is Athena SOC 2 compliant?

Yes. Athena is SOC 2 Type II and HIPAA compliant. Contact [team@athenaintel.com](mailto:team@athenaintel.com) to request compliance documentation.

## Does Athena train on my data?

No. Athena does not use customer data to train, fine-tune or improve any model, and this is part of the customer contract. Athena's model providers operate under contractual **zero-data-retention** agreements: data sent to them for processing is not stored or used for training.

## Does Athena store data from my connected systems?

Not permanently. When you connect SharePoint, OneDrive, Google Drive, iManage, Snowflake and similar systems as [Live Assets](/docs/connect-your-data/live-assets), files and records stay in the source system:

* Athena fetches content on demand, as the signed-in user.
* To avoid repeated fetches, file contents are kept in an encrypted, short-lived cache that expires after one hour by default.
* Athena keeps only the metadata and identifiers needed to find the item again.

Files you [upload directly](/docs/connect-your-data/import) are stored in Athena's secure storage so they can be converted, searched and reused.

## How does Athena handle permissions on connected data?

With a per-user connection, each user connects their own account, usually through OAuth, so Athena acts as that person. Access is checked against the source system every time a Live Asset is opened. If someone loses access to a file in the source system, they lose it in Athena at the same moment. Agents get the same permissions as the person they work for.

Some integrations also offer a shared connection, such as a BigQuery service account or an admin-registered SharePoint app. Requests on a shared connection run with that account's rights, not each user's, so use per-user connections where individual permissions must apply.

Most integrations support per-user sign-in:

| Integration | How access is controlled |
| - | - |
| [SharePoint](/docs/connect-your-data/sharepoint), [OneDrive](/docs/connect-your-data/onedrive) | Per-user Microsoft OAuth, where each user's permissions apply; SharePoint also has an [admin-registered app](/docs/connect-your-data/o365) option that uses the app's permissions |
| [Snowflake](/docs/connect-your-data/snowflake) | Per-user OAuth or credentials, scoped to a Snowflake role |
| [BigQuery](/docs/integrations/bigquery) | Google sign-in, where each user's IAM permissions apply, or a service account, where its IAM roles apply |
| [Databricks](/docs/integrations/databricks) | Per-user OAuth; Unity Catalog ACLs apply |
| [Azure SQL](/docs/integrations/azure-sql), [Azure Blob](/docs/integrations/azure-blob), [Power BI](/docs/integrations/powerbi) | Per-user Microsoft Entra sign-in; Azure and Power BI permissions apply |
| [Jira](/docs/integrations/jira), [Confluence](/docs/integrations/confluence) | Per-user Atlassian OAuth; project and space permissions apply |

## Does Athena support SSO and SCIM?

Yes. Athena supports SAML 2.0 and OIDC single sign-on with Microsoft Entra ID, Okta, Google Workspace and any compliant identity provider. Your identity provider's MFA policies apply to Athena logins. With SCIM, users you deactivate in your identity provider are deactivated in Athena automatically. See [Single Sign-On (SSO)](/docs/getting-started/sso).

## Can Athena be deployed in my own cloud?

Yes. Athena offers four deployment models:

| Model | Where Athena runs |
| - | - |
| Managed cloud | Run and monitored by Athena; the fastest path to production |
| Your VPC | Inside your own cloud account and network boundary on AWS (including GovCloud), Azure or GCP |
| On-premises | In your data center, under your controls |
| Air-gapped | Fully isolated, with no outbound connectivity required |

The no-training commitment applies in every deployment model. See [deployment options](https://athenaintel.com/deployment-options).

## Can I see and undo what Athena did?

Yes. Every change made by a person or an agent is attributed to whoever made it, and changes can be undone. [AOPs](/docs/pillars/applications/aops) are versioned, so you can see who changed a procedure and when, and restore any earlier version. Athena's answers cite their sources with [deep links](/docs/pillars/contextual-knowledge/citations-deep-linking) to the exact passage, page or cell.

## Related pages

* [Live Assets: use external data without copying it](/docs/connect-your-data/live-assets)
* [Single Sign-On (SSO), SAML, OIDC and SCIM](/docs/getting-started/sso)
* [SharePoint enterprise setup with Azure App Registration](/docs/connect-your-data/o365)
* [All integrations](/docs/connect-your-data/all-integrations)
* [Athena governance controls](https://athenaintel.com/governance)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.