Security

Trust for financial advice data.

Athena is SOC 2 Type II compliant and built on AWS so client AI, investing supervision, communication, and acquisition can run with auditability — not as an unsupervised black box.

Request SOC 2 report   Book a demo

SOC 2 Type II

Independent controls attestation

AWS

Cloud foundation for the platform

Bedrock

Governed AI with Guardrails

IaC

Infrastructure as code, reviewed & repeatable

At a glance

Held to the bar financial advice data demands.

A short list for diligence. Deeper architecture and how to request the report are below.

SOC 2 Type II

Independent attestation of control operating effectiveness over a period.

Encryption & isolation

Data protected in transit and at rest; workloads designed for least privilege.

Governed AI

Amazon Bedrock with Guardrails — content and PII policies on AI surfaces.

Evidence trail

Logging and supervision so examiners can ask what happened — and get an answer.

Request SOC 2 report

Compliance program

How we stay audit-ready between exams.

Practices that support SOC 2 Type II for a modern financial platform — continuous monitoring, evidence readiness, and clear diligence paths for buyers.

Continuous control monitoring

Security and compliance controls are monitored on an ongoing cadence — not only during annual audit season — so drift can be spotted and remediated before diligence asks.

Evidence readiness

Control evidence is collected and organized so customer diligence, security questionnaires, and auditor requests can move faster without ad-hoc screenshot hunts.

Formal policies

Information security, access, and operational policies are maintained as living documents that map to SOC 2 control expectations — reviewed as the product and infra evolve.

Access reviews

Employee and operator access is subject to periodic review so privileges stay aligned with role — especially important across client, reporting, and Mission Control surfaces.

Vendor & subprocessors

Critical vendors that touch infrastructure, observability, or customer data are tracked through a vendor-risk process appropriate for a SOC 2 Type II program.

Audit cadence

Independent SOC 2 Type II examination covers the operating effectiveness of controls over a period — the standard RIA and enterprise buyers expect for financial platforms.

Data protection

Encrypt, scope, and keep secrets out of code.

Financial platforms earn trust when encryption and access patterns are boringly consistent — in transit, at rest, and across service roles.

Encryption in transit

Client and API traffic is designed to use TLS (TLS 1.2+) at the edge. Sensitive service-to-service paths stay inside the AWS network where practical.

Encryption at rest

Core data stores and object storage are encrypted at rest. Sensitive reporting tables use customer-managed KMS keys with key rotation enabled.

Secrets management

Operational secrets are designed to live in AWS Secrets Manager — retrieved by scoped service roles, not hard-coded into application images.

Least-privilege access

Infrastructure and application roles follow least-privilege IAM patterns so services receive only the permissions required for their job.

Infrastructure

AWS, designed as code.

Athena’s production posture is grounded in Amazon Web Services with CloudFormation-managed infrastructure — so network, identity, data, and AI controls can be reviewed and reproduced.

01

Isolated network design

VPC · private subnets · multi-AZ. Application workloads run in Amazon VPC with private subnets across availability zones. Services are designed to run behind private load balancing — not as publicly exposed task hosts.

02

Hardened edge

CloudFront · WAF · TLS. Public surfaces terminate TLS at the edge. AWS WAF managed rule sets help filter common web exploits before traffic reaches application layers.

03

Repeatable infrastructure

CloudFormation · Stacker. Environments are provisioned with AWS CloudFormation (infrastructure as code) so network, identity, data, and AI controls can be reviewed, versioned, and reproduced across stages.

04

Observable operations

CloudTrail · CloudWatch · Datadog. API activity monitoring, service health alarms, and application observability are part of the operating model — so unusual changes and production issues can be investigated quickly.

AI & data use

Amazon Bedrock with Guardrails, not a free-form model.

Athena’s AI layer runs on Amazon Bedrock. Under AWS Bedrock’s standard commercial terms, customer content is not used to train the underlying foundation models. Bedrock Guardrails help enforce content filters and sensitive-information policies, including PII anonymization patterns, on AI chat paths.

Bedrock GuardrailsOn
Content filter Active
PII anonymization Active
Train on customer content Off
Models explain, engines decide Human escalate

Access & supervision

Identity, roles, and humans in the loop.

Security is not only encryption. Operator identity uses Amazon Cognito with MFA options on client and advisor pools, short-lived tokens, and group and scope packages so Mission Control, reporting, and tooling can be granted by duty. Product supervision keeps exceptions and approvals visible, not buried in a side spreadsheet.

Mission ControlApprovals
Cash request Needs you
Trade exception In queue
Creative review Gated
Scoped operator package Cognito · MFA

Financial data operating model

Designed for advice, custody context, and firm operators.

What strong fintech and RIA platforms emphasize — sensitivity of client data, separation of duties, and recovery readiness — adapted to how Athena actually runs.

Financial data sensitivity

Household PII, account context, and AUM-related signals are treated as regulated-practice data — not generic SaaS telemetry. Design choices favor isolation, scoped access, and reconstructable activity.

Role-based operator access

Advisor and operations surfaces use Cognito-backed identity with group and OAuth-scope packages — so reporting, Mission Control, and tooling access can be granted by duty, not as a flat admin model.

Tenant-aware reporting walls

Mission Control and reporting paths are designed with domain and package isolation so operators see the book they are authorized for — fail-closed when tenancy cannot be resolved.

Recovery readiness

Critical DynamoDB tables enable point-in-time recovery. Object storage for user uploads uses server-side encryption and blocks public bucket access by default.

Diligence

What buyers should ask any agentic platform

Athena is designed so those answers live in the product and the compliance program, not only in a slide deck after the demo.

Where do humans still approve?

Can you reconstruct what a client saw and when?

How is PII and account data encrypted and accessed?

How does marketing creative clear compliance?

What happens when the model is wrong?

Can we review your SOC 2 Type II report?

Security & trust

Security & trust FAQs

Is Athena SOC 2 Type II compliant?

Yes. Athena maintains SOC 2 Type II compliance. Firms evaluating Athena can request the report and related trust materials through a demo or by emailing contact@advicebyathena.com.

Where does Athena run?

Athena runs on Amazon Web Services. Core application services are deployed in VPC private subnets with infrastructure defined as CloudFormation — reviewed, repeatable, and environment-aware.

How is client and AI data handled?

Data is encrypted in transit and at rest. Athena’s AI layer uses Amazon Bedrock. Under AWS Bedrock’s standard commercial terms, customer content is not used to train the underlying foundation models. Guardrails help enforce content and sensitive-information policies on AI chat paths.

Is Athena an unsupervised black box?

No. Core recommendations come from deterministic engines and simulations; AI explains in firm voice; Mission Control surfaces exceptions; humans approve edge cases. Audit-friendly trails are part of the product thesis.

How does acquisition creative stay compliant?

Ad tech includes a compliance gate before publish. Firms remain responsible for marketing posture — Athena’s thesis is to make supervision part of the platform.

How do I request a SOC 2 report or complete a security questionnaire?

Email contact@advicebyathena.com with your firm name and what you need (SOC 2 Type II report, security questionnaire, or architecture overview), or book a demo and ask for trust materials. We’ll route diligence requests to the right owners.