SOC 2 Type II Certified

Security & Trust

Athian is built to handle sensitive supplier evidence safely. Here’s how we protect your data — and your buyers’ trust.

How we protect your data

Four commitments that remove the vendor-risk question before it comes up.

SOC 2 Type II Certified

Athian has completed an independent SOC 2 Type II audit covering Security, Availability, and Confidentiality trust service criteria. Our controls are tested continuously — not just at a point in time — so you can rely on them every day your data is in our care. A copy of the report is available to qualified prospects on request.

Customer Data Isolated at the Database Layer

Every customer account runs against its own isolated database schema. Your supplier evidence never shares storage rows with another organization's data. Even in the event of an application-layer bug, cross-tenant data access is blocked at the database boundary — not just by application logic.

Zero Standing Engineering Access to Production Data

No Athian engineer holds permanent credentials to the production database. All access to production systems is just-in-time, requires explicit approval, is scoped to the minimum permission needed, and is fully logged. There is no back-door access that bypasses these controls. Every access event is auditable.

Evidence Chain Encrypted, Access-Controlled & Auditable

All supplier evidence — documents, images, sensor data — is encrypted at rest (AES-256) and in transit (TLS 1.2+). Access to evidence records is scoped by role and requires authentication; no evidence is publicly reachable by URL alone. Every read, write, and share event is logged to an immutable audit trail, giving you a complete chain of custody from submission to final report.

More about our practices

Data Retention & Deletion

We retain customer data for the duration of your subscription and for a defined period after contract termination to support any audit or dispute process. You may request deletion of your data at any time. Full details on retention schedules and deletion procedures are available on request — contact your account team or reach out to us.

Subprocessors

Athian uses a limited set of vetted third-party subprocessors to deliver core platform services (cloud infrastructure, monitoring, and communications). All subprocessors are contractually bound to equivalent data protection obligations. A current subprocessor list is available to customers on request.

Request Our SOC 2 Report

Qualified prospects and existing customers may request a copy of our SOC 2 Type II report under NDA. To request the report, contact our team and we will respond within one business day.

Questions about our security practices?

Our team is happy to walk you through our controls, share the SOC 2 report, or answer any vendor-risk questions your procurement team has.