SOC 2 Type II
Independent controls attestation
Security
Athena is SOC 2 Type II compliant and built on AWS so client AI, investing supervision, communication, and acquisition can run with auditability — not as an unsupervised black box.
Independent controls attestation
Cloud foundation for the platform
Governed AI with Guardrails
Infrastructure as code, reviewed & repeatable
At a glance
A short list for diligence. Deeper architecture and how to request the report are below.
Independent attestation of control operating effectiveness over a period.
Data protected in transit and at rest; workloads designed for least privilege.
Amazon Bedrock with Guardrails — content and PII policies on AI surfaces.
Logging and supervision so examiners can ask what happened — and get an answer.
Compliance program
Practices that support SOC 2 Type II for a modern financial platform — continuous monitoring, evidence readiness, and clear diligence paths for buyers.
Security and compliance controls are monitored on an ongoing cadence — not only during annual audit season — so drift can be spotted and remediated before diligence asks.
Control evidence is collected and organized so customer diligence, security questionnaires, and auditor requests can move faster without ad-hoc screenshot hunts.
Information security, access, and operational policies are maintained as living documents that map to SOC 2 control expectations — reviewed as the product and infra evolve.
Employee and operator access is subject to periodic review so privileges stay aligned with role — especially important across client, reporting, and Mission Control surfaces.
Critical vendors that touch infrastructure, observability, or customer data are tracked through a vendor-risk process appropriate for a SOC 2 Type II program.
Independent SOC 2 Type II examination covers the operating effectiveness of controls over a period — the standard RIA and enterprise buyers expect for financial platforms.
Data protection
Financial platforms earn trust when encryption and access patterns are boringly consistent — in transit, at rest, and across service roles.
Client and API traffic is designed to use TLS (TLS 1.2+) at the edge. Sensitive service-to-service paths stay inside the AWS network where practical.
Core data stores and object storage are encrypted at rest. Sensitive reporting tables use customer-managed KMS keys with key rotation enabled.
Operational secrets are designed to live in AWS Secrets Manager — retrieved by scoped service roles, not hard-coded into application images.
Infrastructure and application roles follow least-privilege IAM patterns so services receive only the permissions required for their job.
Infrastructure
Athena’s production posture is grounded in Amazon Web Services with CloudFormation-managed infrastructure — so network, identity, data, and AI controls can be reviewed and reproduced.
VPC · private subnets · multi-AZ. Application workloads run in Amazon VPC with private subnets across availability zones. Services are designed to run behind private load balancing — not as publicly exposed task hosts.
CloudFront · WAF · TLS. Public surfaces terminate TLS at the edge. AWS WAF managed rule sets help filter common web exploits before traffic reaches application layers.
CloudFormation · Stacker. Environments are provisioned with AWS CloudFormation (infrastructure as code) so network, identity, data, and AI controls can be reviewed, versioned, and reproduced across stages.
CloudTrail · CloudWatch · Datadog. API activity monitoring, service health alarms, and application observability are part of the operating model — so unusual changes and production issues can be investigated quickly.
AI & data use
Athena’s AI layer runs on Amazon Bedrock. Under AWS Bedrock’s standard commercial terms, customer content is not used to train the underlying foundation models. Bedrock Guardrails help enforce content filters and sensitive-information policies, including PII anonymization patterns, on AI chat paths.
Access & supervision
Security is not only encryption. Operator identity uses Amazon Cognito with MFA options on client and advisor pools, short-lived tokens, and group and scope packages so Mission Control, reporting, and tooling can be granted by duty. Product supervision keeps exceptions and approvals visible, not buried in a side spreadsheet.
Financial data operating model
What strong fintech and RIA platforms emphasize — sensitivity of client data, separation of duties, and recovery readiness — adapted to how Athena actually runs.
Household PII, account context, and AUM-related signals are treated as regulated-practice data — not generic SaaS telemetry. Design choices favor isolation, scoped access, and reconstructable activity.
Advisor and operations surfaces use Cognito-backed identity with group and OAuth-scope packages — so reporting, Mission Control, and tooling access can be granted by duty, not as a flat admin model.
Mission Control and reporting paths are designed with domain and package isolation so operators see the book they are authorized for — fail-closed when tenancy cannot be resolved.
Critical DynamoDB tables enable point-in-time recovery. Object storage for user uploads uses server-side encryption and blocks public bucket access by default.
Diligence
Athena is designed so those answers live in the product and the compliance program, not only in a slide deck after the demo.
Where do humans still approve?
Can you reconstruct what a client saw and when?
How is PII and account data encrypted and accessed?
How does marketing creative clear compliance?
What happens when the model is wrong?
Can we review your SOC 2 Type II report?
Security & trust
Yes. Athena maintains SOC 2 Type II compliance. Firms evaluating Athena can request the report and related trust materials through a demo or by emailing contact@advicebyathena.com.
Athena runs on Amazon Web Services. Core application services are deployed in VPC private subnets with infrastructure defined as CloudFormation — reviewed, repeatable, and environment-aware.
Data is encrypted in transit and at rest. Athena’s AI layer uses Amazon Bedrock. Under AWS Bedrock’s standard commercial terms, customer content is not used to train the underlying foundation models. Guardrails help enforce content and sensitive-information policies on AI chat paths.
No. Core recommendations come from deterministic engines and simulations; AI explains in firm voice; Mission Control surfaces exceptions; humans approve edge cases. Audit-friendly trails are part of the product thesis.
Ad tech includes a compliance gate before publish. Firms remain responsible for marketing posture — Athena’s thesis is to make supervision part of the platform.
Email contact@advicebyathena.com with your firm name and what you need (SOC 2 Type II report, security questionnaire, or architecture overview), or book a demo and ask for trust materials. We’ll route diligence requests to the right owners.