What you can count on Operating today
- Your own instance. A separate database and application per customer, with row-level security enforced in the database, not just the interface.
- Self-hosted AI. The model runs on infrastructure we operate. It assists and surfaces findings; a person always makes the call, and it can be turned off without changing your records. No third-party AI vendor ever sees your data, and nothing is used to train a model.
- No worker is ever scored or ranked. Coaching themes are reported by plant, department, and shift, never by name.
- Encryption everywhere. TLS 1.2 or higher in transit; AES-256 at rest.
- Your identity provider. Single sign-on over SAML 2.0, so access, MFA, and de-provisioning stay governed by your IdP, and we never see credentials.
- Disclosed sub-processors. Supabase, Vercel, Modal, and transactional email/SMS. See the full list.
- Breach notification. We notify you of a confirmed breach affecting your data within 72 hours.
The full security package
For your security and legal review, we share a complete package: a filled-out CAIQ, our ISMS control mapping to ISO 27001, and the architecture detail. We are not independently certified yet, and the package states plainly what operates today and what is on our roadmap.
Request the package security@athenaforms.ai
Report a vulnerability security@athenaforms.ai
