AthenaHQ enterprise security, SSO, SOC 2 and procurement
An evidence-backed AthenaHQ enterprise security review covering SOC 2, GDPR, NIST CSF, SAML and OIDC SSO, RBAC, audit logs, DPA terms, subprocessors, residency, SLA, and Trakkr tradeoffs.
Quick answer
Does AthenaHQ meet enterprise identity, security, privacy, legal, and procurement requirements?
AthenaHQ has the stronger public certification case: its Trust Center lists SOC 2 Type 1 and Type 2, and its Enterprise page dates Type 2 to June 2026. Enterprise adds SAML or OIDC SSO, audit logs, custom access controls, GDPR claims, and NIST CSF 2.0 Tier 3. A DPA and subprocessor list are public. The main open item is selectable data residency, while public support documents also differ between a two-hour and one-business-day response target.
Key facts and evidence
- SOC 2
- Type 1 and Type 2 listed; Type 2 dated June 2026Evidence: AthenaHQ Trust Center, AthenaHQ Enterprise
- SSO
- SAML or OIDC on Enterprise; Google and Microsoft OAuth also namedEvidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview
- Roles
- Unlimited seats and RBAC on Starter; custom access controls on EnterpriseEvidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview
- Audit trail
- Organization activity audit log is Enterprise-onlyEvidence: AthenaHQ plans and pricing
- Data processing
- Public DPA dated 24 August 2026 with a named subprocessor tableEvidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust CenterNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.
- Availability
- Public MSA states 99.9 percent monthly availability with exclusionsEvidence: AthenaHQ Master Service Agreement
AthenaHQ and Trakkr enterprise procurement evidence
| Control area | AthenaHQ | Trakkr | Procurement check |
|---|---|---|---|
| Vendor certification | Trust Center lists SOC 2 Type 1 and Type 2 | Trakkr says its infrastructure providers are certified but Trakkr is not yet SOC 2 certified | Request the report, scope, period, exceptions, bridge letter, and current remediation statusEvidence: AthenaHQ Trust Center, AthenaHQ Enterprise, Security at Trakkr |
| Identity and roles | RBAC on Starter; SAML or OIDC SSO and custom controls on Enterprise | RBAC and MFA are publicly documented | Map IdP groups, joiner and leaver flow, admin recovery, and client accessEvidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview, Security at Trakkr |
| Auditability | Organization activity audit log is listed on Enterprise | This comparison makes no Trakkr organization-audit-log claim | Test event scope, actor identity, IP, retention, export, and API accessEvidence: AthenaHQ plans and pricing |
| Data location | DPA lists mostly United States or United States/global processing locations | Trakkr says data uses certified regions and regional isolation | Neither statement alone proves a customer-selectable residency commitmentEvidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust Center, Security at TrakkrNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form. |
| Service terms | 99.9 percent availability; public support targets differ by document | Trakkr says security questions typically receive a response within 24 hours | Put severities, hours, response and resolution targets, credits, and escalation in the order formEvidence: AthenaHQ Master Service Agreement, AthenaHQ plans and pricing, Security at TrakkrVerification: partially verified. The two documents may govern different plans or severities. Procurement should confirm the order-form response matrix, support hours, escalation path, and remedies. |
| DPA and subprocessors | Public DPA covers core processor obligations and names current service providers | Trakkr publishes a transparent subprocessor and privacy posture | Review transfer mechanism, change notice, deletion, support access, and high-risk AI providersEvidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust Center, Security at TrakkrNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form. |
Public badges and policy indexes are screening evidence. A regulated buyer still needs the gated reports, order form, security questionnaire, architecture answers, and negotiated terms.
Is AthenaHQ SOC 2 Type 2 certified?
Yes, based on AthenaHQ's current public evidence. Its Trust Center lists SOC 2 Type 1 and Type 2, and the Enterprise page dates Type 1 to October 2025 and Type 2 to June 2026.
The full report is gated. A buyer should request it and verify the legal entity, in-scope services, audit period, trust criteria, exceptions, subservice organizations, management responses, and bridge coverage through the planned go-live date.
Which AthenaHQ identity, role, and audit controls are plan-gated?
Starter publishes unlimited seats, role-based access control, and Google or Microsoft OAuth. Enterprise adds SAML or OIDC SSO, custom access controls, and an organization activity audit log.
The public plan table does not define every role, SSO provisioning path, SCIM support, session rule, audit event, retention period, or export format. Those are acceptance-test items rather than safe inferences from the feature labels.
What do AthenaHQ's DPA and public hosting information say about data location?
The DPA covers processing instructions, risk-based safeguards, authorized subprocessors, rights assistance, incident notice, deletion or return, audit rights, and transfers. Its subprocessor table places most listed processing in the United States or United States/global locations.
The public legal and security pages do not document a customer-selectable residency menu. If EU, UK, or another jurisdiction must contain primary data, backups, logs, inference, and support access, write each location and exception into the contract.
What service and support commitments does AthenaHQ publish?
The public MSA states 99.9 percent monthly availability, with exclusions and service-credit terms for qualifying downtime. Its general support exhibit says AthenaHQ will use commercially reasonable efforts to respond within one business day during stated support hours.
The current plan comparison advertises a two-hour SLA for Enterprise. The documents may address different plans or severities, so procurement should confirm which promise controls, whether it is response or resolution, and what remedies apply.
Evidence and method
Certification evidence is current and dated
AthenaHQ's Trust Center and Enterprise page align on Type 1 and Type 2, with the Enterprise page dating the Type 2 audit to June 2026.
Evidence: AthenaHQ Trust Center, AthenaHQ EnterpriseEnterprise identity gates are explicit
The plan table distinguishes Starter RBAC and OAuth from Enterprise SAML or OIDC SSO, custom controls, and organization activity audit logs.
Evidence: AthenaHQ plans and pricing, AthenaHQ product and plan overviewThe DPA exposes meaningful diligence inputs
AthenaHQ publishes core processor commitments and a named subprocessor list with processing locations, which lets buyers review material data flows before a sales call.
Evidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust CenterNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.Support language needs contract reconciliation
The public Enterprise plan and MSA show different response targets, making the negotiated order form and severity matrix the only safe operational commitment.
Evidence: AthenaHQ plans and pricing, AthenaHQ Master Service AgreementVerification: partially verified. The two documents may govern different plans or severities. Procurement should confirm the order-form response matrix, support hours, escalation path, and remedies.How we checked this page
We separated certification, technical controls, identity, auditability, privacy terms, subprocessor location, residency, availability, and support because procurement cannot substitute one for another.
- 1. Checked AthenaHQ's current Trust Center, Enterprise and plans pages, DPA, privacy policy, and MSA for explicit controls, dates, plan gates, and legal commitments.
- 2. Marked selectable residency as not publicly documented because a transfer clause and global processing list do not prove that a buyer can choose a hosting region.
- 3. Compared Trakkr only from its current official security page and preserved its explicit statement that Trakkr does not yet hold its own SOC 2 certification.
- Limitation: We did not receive the gated SOC 2 reports, complete a vendor questionnaire, test SSO, inspect architecture, or negotiate an order form.
- Limitation: Control scope, exceptions, retention, recovery targets, support severity, and residency can only be confirmed in due diligence and contract documents.
When is AthenaHQ or Trakkr the better procurement fit?
AthenaHQ is the stronger documented choice when vendor-level SOC 2 Type 2, Enterprise SAML or OIDC SSO, organization audit logs, and a public DPA with named processing locations are hard requirements. Buyers should still reconcile support targets and put any residency requirement in writing.
Trakkr remains a fit when procurement accepts its published TLS, AES-256, row-level isolation, RBAC, MFA, regional infrastructure posture, and certified providers. Trakkr openly says it does not yet hold its own SOC 2 certification, so AthenaHQ has the clear certification advantage today.
Yes. AthenaHQ's Trust Center lists SOC 2 Type 2, and its Enterprise page dates Type 2 to June 2026. Request the gated report to verify scope, period, and exceptions.
Yes on Enterprise. AthenaHQ names both SAML and OIDC SSO, while Starter publishes Google and Microsoft OAuth plus role-based access control without Enterprise SSO.
AthenaHQ lists an organization activity audit log on Enterprise and not on Starter. Ask which events, actors, IP fields, retention, exports, and API access are included.
A customer-selectable residency option is not publicly documented. AthenaHQ lists mostly United States or global processing locations and transfer safeguards, so a hard residency rule needs written contract terms.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.