Security at AthenaMi
AthenaMi uses layered technical and operational safeguards designed to protect platform access, customer data, and governed engagement evidence.
AthenaMi is designed to minimize security exposure by design: we do not send client marketing campaigns, and we avoid unnecessary recipient personal identifiers. Engagement evidence is handled in a campaign-scoped context and surfaced only through governed outputs.
This page summarizes the security practices and operational safeguards used to protect AthenaMi systems and data.
- Covers: access control, data handling, auditability, operational monitoring, and incident response.
- Does not cover: client-controlled outbound messaging systems, recipient lists, or client-side security configurations.
- Wallet posture: AthenaMi records operational transaction metadata and platform fees; it is not a bank and does not hold customer funds as a deposit institution.
- Account access is restricted to authorized operators within a workspace.
- Role membership is used to control what data and actions are available.
- Access patterns are designed to be auditable and explainable.
- Administrative actions are restricted and intended to be reviewable.
- We use encryption in transit and rely on industry-standard mechanisms for secure transport.
- We apply least-privilege access to stored data and limit exposure where possible.
- We aim to separate operational metadata from governed outputs and minimize unnecessary fields.
No method of transmission or storage is completely secure. AthenaMi uses layered technical and operational safeguards appropriate to the platform and the data it processes.
- We maintain logs and operational telemetry to support reliability and security investigations.
- Key events are intended to be attributable and campaign-scoped where applicable.
- We favor explainable states over opaque automation.
- Contain and mitigate impact (including access restriction when needed).
- Investigate with available logs and system traces.
- Coordinate notification consistent with contractual and legal requirements.
- Document learnings and strengthen controls to prevent recurrence.
AthenaMi relies on established infrastructure and service providers where appropriate (for example, hosting, monitoring, and payment rails). We apply technical and operational safeguards to limit access and exposure across these dependencies.
We aim to keep the platform’s dependency footprint minimal and auditable.
If you believe you have discovered a security vulnerability, please report it in good faith. Do not attempt to access data that does not belong to you, disrupt service availability, or publicize findings before we have an opportunity to respond.
Send reports to: security@athenami.com