Security

Diligence answers live in the product, not only in a slide after the demo.

Athena maintains SOC 2 Type II compliance and runs on Amazon Web Services. Client AI, investing supervision, communication, and acquisition leave an evidence trail you can reconstruct. Engines produce recommendations; Athena AI explains them; Mission Control surfaces exceptions; and people approve the edge cases. The rest of this page names the controls a diligence reviewer usually asks for first, then walks the compliance program, data protection, infrastructure, AI terms, and access model. REGISTER ONLY (trust chips — UI chrome only, not body claims): - SOC 2 Type II — Independent controls attestation over a period - AWS — Cloud foundation for the platform - Bedrock — Governed AI with Guardrails - IaC — Infrastructure as code, reviewed and repeatable

Request SOC 2 report   Book a demo

SOC 2 Type II

Independent controls attestation

AWS

Cloud foundation for the platform

Bedrock

Governed AI with Guardrails

IaC

Infrastructure as code, reviewed & repeatable

At a glance

Held to the bar financial advice data demands.

A short list for diligence. Deeper architecture and how to request the report are below.

SOC 2 Type II

Independent attestation of control operating effectiveness over a period.

Encryption & isolation

Data protected in transit and at rest; workloads designed for least privilege.

Governed AI

Amazon Bedrock with Guardrails — content and PII policies on AI surfaces.

Evidence trail

Logging and supervision so examiners can ask what happened — and get an answer.

Request SOC 2 report

Compliance program

How the program stays ready between exams

Practices that support SOC 2 Type II for a financial advice platform include ongoing monitoring, evidence you can hand over, and a clear path when a questionnaire arrives. The program is built so drift can be fixed before diligence asks, rather than only during annual audit season.

Security and compliance controls are watched on an ongoing cadence. Control evidence is collected and organized so customer diligence, security questionnaires, and auditor requests move without an ad-hoc screenshot hunt. Information security, access, and operational policies are maintained as living documents that map to SOC 2 control expectations and are reviewed as the product and infrastructure change. Employee and operator access gets periodic review so privileges stay aligned with role across client, reporting, and Mission Control surfaces. Critical vendors that touch infrastructure, observability, or customer data go through a vendor-risk process appropriate for a SOC 2 Type II program. Independent SOC 2 Type II examination covers operating effectiveness of controls over a period—the bar RIA and enterprise buyers expect for financial platforms.

Continuous control monitoring

Security and compliance controls are monitored on an ongoing cadence — not only during annual audit season — so drift can be spotted and remediated before diligence asks.

Evidence readiness

Control evidence is collected and organized so customer diligence, security questionnaires, and auditor requests can move faster without ad-hoc screenshot hunts.

Formal policies

Information security, access, and operational policies are maintained as living documents that map to SOC 2 control expectations — reviewed as the product and infra evolve.

Access reviews

Employee and operator access is subject to periodic review so privileges stay aligned with role — especially important across client, reporting, and Mission Control surfaces.

Vendor & subprocessors

Critical vendors that touch infrastructure, observability, or customer data are tracked through a vendor-risk process appropriate for a SOC 2 Type II program.

Audit cadence

Independent SOC 2 Type II examination covers the operating effectiveness of controls over a period — the standard RIA and enterprise buyers expect for financial platforms.

Data protection

Encrypt, scope, and keep secrets out of code

Encryption and access patterns stay consistent in transit, at rest, and across service roles, so a diligence questionnaire does not get a different story in each environment.

Client and API traffic is designed to use TLS (TLS 1.2+) at the edge, and sensitive service-to-service paths stay inside the AWS network where practical. Core data stores and object storage are encrypted at rest; sensitive reporting tables use customer-managed KMS keys with key rotation enabled. Operational secrets are designed to live in AWS Secrets Manager, retrieved by scoped service roles, not hard-coded into application images. Infrastructure and application roles follow least-privilege IAM patterns so services receive only the permissions required for their job.

Encryption in transit

Client and API traffic is designed to use TLS (TLS 1.2+) at the edge. Sensitive service-to-service paths stay inside the AWS network where practical.

Encryption at rest

Core data stores and object storage are encrypted at rest. Sensitive reporting tables use customer-managed KMS keys with key rotation enabled.

Secrets management

Operational secrets are designed to live in AWS Secrets Manager — retrieved by scoped service roles, not hard-coded into application images.

Least-privilege access

Infrastructure and application roles follow least-privilege IAM patterns so services receive only the permissions required for their job.

Infrastructure

AWS, designed as code

Athena’s production posture sits on Amazon Web Services with CloudFormation-managed infrastructure so network, identity, data, and AI controls can be reviewed and reproduced across stages.

Application workloads run in Amazon VPC with private subnets across availability zones, behind private load balancing rather than as publicly exposed task hosts. Public surfaces terminate TLS at the edge; AWS WAF managed rule sets help filter common web exploits before traffic reaches application layers. Environments are provisioned with AWS CloudFormation (infrastructure as code) so network, identity, data, and AI controls can be reviewed, versioned, and reproduced. API activity monitoring, service health alarms, and application observability—CloudTrail, CloudWatch, and Datadog—are part of the operating model so unusual changes and production issues can be investigated quickly.

01

Isolated network design

VPC · private subnets · multi-AZ. Application workloads run in Amazon VPC with private subnets across availability zones. Services are designed to run behind private load balancing — not as publicly exposed task hosts.

02

Hardened edge

CloudFront · WAF · TLS. Public surfaces terminate TLS at the edge. AWS WAF managed rule sets help filter common web exploits before traffic reaches application layers.

03

Repeatable infrastructure

CloudFormation · Stacker. Environments are provisioned with AWS CloudFormation (infrastructure as code) so network, identity, data, and AI controls can be reviewed, versioned, and reproduced across stages.

04

Observable operations

CloudTrail · CloudWatch · Datadog. API activity monitoring, service health alarms, and application observability are part of the operating model — so unusual changes and production issues can be investigated quickly.

AI & data use

Amazon Bedrock with Guardrails, not a free-form model

Athena’s AI layer runs on Amazon Bedrock. Under AWS Bedrock’s standard commercial terms, customer content is not used to train the underlying foundation models. Bedrock Guardrails help enforce content filters and sensitive-information policies, including PII anonymization patterns, on AI chat paths. Models explain methodology in firm voice; engines decide the recommendation; humans escalate the exceptions. That split is the same story as Athena AI and the planning methodology guide.

For a diligence reader, the important residue is reconstructability: what the client asked, what the engines proposed, what the model explained, and what a person approved or sent back in Mission Control. Athena AI is not a free-form advice black box bolted beside the book. It sits on the household record next to overnight investing, advice-triggered communication, and the compliance gate for acquisition creative.

Bedrock GuardrailsOn
Content filter Active
PII anonymization Active
Train on customer content Off
Models explain, engines decide Human escalate

Access & supervision

Identity, roles, and humans in the loop

Operator identity uses Amazon Cognito with MFA options on client and advisor pools, short-lived tokens, and group and scope packages so Mission Control, reporting, and tooling can be granted by duty rather than as a flat admin model. Product supervision keeps exceptions and approvals visible on the household, not buried in a side spreadsheet. Cash requests, trade exceptions, and creative review show up where an operator can approve, change, or send back without rebuilding the file from a blotter and a separate CRM.

Mission Control is the household CRM for this book, so the conversation record, the overnight investing exceptions, and the advice-triggered messages an examiner asks about sit on one reconstructable household. Schwab remains the custodial connection for accounts Athena invests; Athena does not replace books and records. Ads on Facebook, Instagram, TikTok, Google, LinkedIn, and YouTube still clear a compliance gate before publish, and the firm remains responsible for marketing posture.

Mission ControlApprovals
Cash request Needs you
Trade exception In queue
Creative review Gated
Scoped operator package Cognito · MFA

Financial data operating model

Built for advice data, custody context, and firm operators

Household PII, account context, and AUM-related signals are treated as regulated-practice data, not generic SaaS telemetry. Design favors isolation, scoped access, and reconstructable activity so a reviewer can follow what a client saw and when. Advisor and operations surfaces use Cognito-backed identity with group and OAuth-scope packages so reporting, Mission Control, and tooling access can be granted by duty, not as a flat admin model. Mission Control and reporting paths are designed with domain and package isolation so operators see the book they are authorized for, and fail closed when tenancy cannot be resolved. Critical DynamoDB tables enable point-in-time recovery; object storage for user uploads uses server-side encryption and blocks public bucket access by default.

Financial data sensitivity

Household PII, account context, and AUM-related signals are treated as regulated-practice data — not generic SaaS telemetry. Design choices favor isolation, scoped access, and reconstructable activity.

Role-based operator access

Advisor and operations surfaces use Cognito-backed identity with group and OAuth-scope packages — so reporting, Mission Control, and tooling access can be granted by duty, not as a flat admin model.

Tenant-aware reporting walls

Mission Control and reporting paths are designed with domain and package isolation so operators see the book they are authorized for — fail-closed when tenancy cannot be resolved.

Recovery readiness

Critical DynamoDB tables enable point-in-time recovery. Object storage for user uploads uses server-side encryption and blocks public bucket access by default.

Diligence

What buyers should ask any agentic platform

Athena is designed so those answers live in the product and the compliance program, not only in a slide deck after the demo.

Where do humans still approve?

Can you reconstruct what a client saw and when?

How is PII and account data encrypted and accessed?

How does marketing creative clear compliance?

What happens when the model is wrong?

Can we review your SOC 2 Type II report?

Security & trust

Security & trust FAQs

Is Athena SOC 2 Type II compliant?

Yes. Athena maintains SOC 2 Type II compliance—an independent attestation of control operating effectiveness over a period. Firms evaluating Athena can request the report and related trust materials through a demo or by emailing contact@advicebyathena.com.

Where does Athena run?

Athena runs on Amazon Web Services. Core application services are deployed in VPC private subnets with private load balancing, TLS at the edge, and infrastructure defined as CloudFormation so network, identity, data, and AI controls can be reviewed and reproduced across stages.

How is client and AI data handled?

Data is encrypted in transit and at rest, with customer-managed KMS keys on sensitive reporting tables where designed. Athena’s AI layer uses Amazon Bedrock. Under AWS Bedrock’s standard commercial terms, customer content is not used to train the underlying foundation models. Guardrails help enforce content and sensitive-information policies, including PII anonymization patterns, on AI chat paths.

Is Athena an unsupervised black box?

No. Core recommendations come from deterministic engines and simulations. Athena AI explains them in firm voice. Mission Control—the household CRM—surfaces exceptions. Humans approve edge cases. Audit-friendly trails of what the client saw and what was approved are part of the product.

How does acquisition creative stay compliant?

Ad tech includes a compliance gate and advisor approval before publish to Facebook, Instagram, TikTok, Google, LinkedIn, and YouTube. Clicks land in the wellness app. Firms remain responsible for marketing posture. Athena’s design is to make supervision part of the platform rather than a side process.

How do I request a SOC 2 report or complete a security questionnaire?

Email contact@advicebyathena.com with your firm name and what you need (SOC 2 Type II report, security questionnaire, or architecture overview), or book a demo and ask for trust materials. Diligence requests route to the right owners so you are not stuck with a marketing slide as the only artifact.

Does Athena replace our CRM or custodian for the security review?

Mission Control is the household CRM; Athena replaces a separate CRM for this book. Charles Schwab is the custodial connection Athena has wired today. Athena does not replace the custodian or the books and records. See Integrations for the stack map.