AthenaHQ logo
AthenaHQ
Enterprise and security

AthenaHQ enterprise security, SSO, SOC 2 and procurement

An evidence-backed AthenaHQ enterprise security review covering SOC 2, GDPR, NIST CSF, SAML and OIDC SSO, RBAC, audit logs, DPA terms, subprocessors, residency, SLA, and Trakkr tradeoffs.

Trakkr editorial teamPublished 2026-08-25
10 min read
Last updated: August 25, 2026

Quick answer

Does AthenaHQ meet enterprise identity, security, privacy, legal, and procurement requirements?

AthenaHQ has the stronger public certification case: its Trust Center lists SOC 2 Type 1 and Type 2, and its Enterprise page dates Type 2 to June 2026. Enterprise adds SAML or OIDC SSO, audit logs, custom access controls, GDPR claims, and NIST CSF 2.0 Tier 3. A DPA and subprocessor list are public. The main open item is selectable data residency, while public support documents also differ between a two-hour and one-business-day response target.

Published by Trakkr. Sources checked 2026-08-25.
Evidence: AthenaHQ Trust Center, AthenaHQ Enterprise, AthenaHQ plans and pricing, AthenaHQ product and plan overview, AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Master Service AgreementNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.Verification: partially verified. The two documents may govern different plans or severities. Procurement should confirm the order-form response matrix, support hours, escalation path, and remedies.
SOC 2
Type 1 and Type 2 listed; Type 2 dated June 2026Evidence: AthenaHQ Trust Center, AthenaHQ Enterprise
SSO
SAML or OIDC on Enterprise; Google and Microsoft OAuth also namedEvidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview
Roles
Unlimited seats and RBAC on Starter; custom access controls on EnterpriseEvidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview
Audit trail
Organization activity audit log is Enterprise-onlyEvidence: AthenaHQ plans and pricing
Data processing
Public DPA dated 24 August 2026 with a named subprocessor tableEvidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust CenterNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.
Availability
Public MSA states 99.9 percent monthly availability with exclusionsEvidence: AthenaHQ Master Service Agreement

AthenaHQ and Trakkr enterprise procurement evidence

AthenaHQ and Trakkr enterprise procurement evidence
Control areaAthenaHQTrakkrProcurement check
Vendor certificationTrust Center lists SOC 2 Type 1 and Type 2Trakkr says its infrastructure providers are certified but Trakkr is not yet SOC 2 certifiedRequest the report, scope, period, exceptions, bridge letter, and current remediation statusEvidence: AthenaHQ Trust Center, AthenaHQ Enterprise, Security at Trakkr
Identity and rolesRBAC on Starter; SAML or OIDC SSO and custom controls on EnterpriseRBAC and MFA are publicly documentedMap IdP groups, joiner and leaver flow, admin recovery, and client accessEvidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview, Security at Trakkr
AuditabilityOrganization activity audit log is listed on EnterpriseThis comparison makes no Trakkr organization-audit-log claimTest event scope, actor identity, IP, retention, export, and API accessEvidence: AthenaHQ plans and pricing
Data locationDPA lists mostly United States or United States/global processing locationsTrakkr says data uses certified regions and regional isolationNeither statement alone proves a customer-selectable residency commitmentEvidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust Center, Security at TrakkrNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.
Service terms99.9 percent availability; public support targets differ by documentTrakkr says security questions typically receive a response within 24 hoursPut severities, hours, response and resolution targets, credits, and escalation in the order formEvidence: AthenaHQ Master Service Agreement, AthenaHQ plans and pricing, Security at TrakkrVerification: partially verified. The two documents may govern different plans or severities. Procurement should confirm the order-form response matrix, support hours, escalation path, and remedies.
DPA and subprocessorsPublic DPA covers core processor obligations and names current service providersTrakkr publishes a transparent subprocessor and privacy postureReview transfer mechanism, change notice, deletion, support access, and high-risk AI providersEvidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust Center, Security at TrakkrNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.

Public badges and policy indexes are screening evidence. A regulated buyer still needs the gated reports, order form, security questionnaire, architecture answers, and negotiated terms.

Is AthenaHQ SOC 2 Type 2 certified?

Yes, based on AthenaHQ's current public evidence. Its Trust Center lists SOC 2 Type 1 and Type 2, and the Enterprise page dates Type 1 to October 2025 and Type 2 to June 2026.

The full report is gated. A buyer should request it and verify the legal entity, in-scope services, audit period, trust criteria, exceptions, subservice organizations, management responses, and bridge coverage through the planned go-live date.

Evidence: AthenaHQ Trust Center, AthenaHQ Enterprise

Which AthenaHQ identity, role, and audit controls are plan-gated?

Starter publishes unlimited seats, role-based access control, and Google or Microsoft OAuth. Enterprise adds SAML or OIDC SSO, custom access controls, and an organization activity audit log.

The public plan table does not define every role, SSO provisioning path, SCIM support, session rule, audit event, retention period, or export format. Those are acceptance-test items rather than safe inferences from the feature labels.

Evidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview

What do AthenaHQ's DPA and public hosting information say about data location?

The DPA covers processing instructions, risk-based safeguards, authorized subprocessors, rights assistance, incident notice, deletion or return, audit rights, and transfers. Its subprocessor table places most listed processing in the United States or United States/global locations.

The public legal and security pages do not document a customer-selectable residency menu. If EU, UK, or another jurisdiction must contain primary data, backups, logs, inference, and support access, write each location and exception into the contract.

Evidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust CenterNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.

What service and support commitments does AthenaHQ publish?

The public MSA states 99.9 percent monthly availability, with exclusions and service-credit terms for qualifying downtime. Its general support exhibit says AthenaHQ will use commercially reasonable efforts to respond within one business day during stated support hours.

The current plan comparison advertises a two-hour SLA for Enterprise. The documents may address different plans or severities, so procurement should confirm which promise controls, whether it is response or resolution, and what remedies apply.

Evidence: AthenaHQ Master Service Agreement, AthenaHQ plans and pricingVerification: partially verified. The two documents may govern different plans or severities. Procurement should confirm the order-form response matrix, support hours, escalation path, and remedies.

Evidence and method

Certification evidence is current and dated

AthenaHQ's Trust Center and Enterprise page align on Type 1 and Type 2, with the Enterprise page dating the Type 2 audit to June 2026.

Evidence: AthenaHQ Trust Center, AthenaHQ Enterprise

Enterprise identity gates are explicit

The plan table distinguishes Starter RBAC and OAuth from Enterprise SAML or OIDC SSO, custom controls, and organization activity audit logs.

Evidence: AthenaHQ plans and pricing, AthenaHQ product and plan overview

The DPA exposes meaningful diligence inputs

AthenaHQ publishes core processor commitments and a named subprocessor list with processing locations, which lets buyers review material data flows before a sales call.

Evidence: AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Trust CenterNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.

Support language needs contract reconciliation

The public Enterprise plan and MSA show different response targets, making the negotiated order form and severity matrix the only safe operational commitment.

Evidence: AthenaHQ plans and pricing, AthenaHQ Master Service AgreementVerification: partially verified. The two documents may govern different plans or severities. Procurement should confirm the order-form response matrix, support hours, escalation path, and remedies.

How we checked this page

We separated certification, technical controls, identity, auditability, privacy terms, subprocessor location, residency, availability, and support because procurement cannot substitute one for another.

  1. 1. Checked AthenaHQ's current Trust Center, Enterprise and plans pages, DPA, privacy policy, and MSA for explicit controls, dates, plan gates, and legal commitments.
  2. 2. Marked selectable residency as not publicly documented because a transfer clause and global processing list do not prove that a buyer can choose a hosting region.
  3. 3. Compared Trakkr only from its current official security page and preserved its explicit statement that Trakkr does not yet hold its own SOC 2 certification.
  • Limitation: We did not receive the gated SOC 2 reports, complete a vendor questionnaire, test SSO, inspect architecture, or negotiate an order form.
  • Limitation: Control scope, exceptions, retention, recovery targets, support severity, and residency can only be confirmed in due diligence and contract documents.

When is AthenaHQ or Trakkr the better procurement fit?

AthenaHQ is the stronger documented choice when vendor-level SOC 2 Type 2, Enterprise SAML or OIDC SSO, organization audit logs, and a public DPA with named processing locations are hard requirements. Buyers should still reconcile support targets and put any residency requirement in writing.

Trakkr remains a fit when procurement accepts its published TLS, AES-256, row-level isolation, RBAC, MFA, regional infrastructure posture, and certified providers. Trakkr openly says it does not yet hold its own SOC 2 certification, so AthenaHQ has the clear certification advantage today.

Evidence: AthenaHQ Trust Center, AthenaHQ Enterprise, AthenaHQ plans and pricing, AthenaHQ product and plan overview, AthenaHQ Data Processing Agreement, AthenaHQ Privacy Policy, AthenaHQ Master Service Agreement, Security at TrakkrNot publicly verified. Global processing and transfer safeguards are not a residency menu. Buyers with a hard location requirement should put hosting and support-access locations in the order form.Verification: partially verified. The two documents may govern different plans or severities. Procurement should confirm the order-form response matrix, support hours, escalation path, and remedies.

Yes. AthenaHQ's Trust Center lists SOC 2 Type 2, and its Enterprise page dates Type 2 to June 2026. Request the gated report to verify scope, period, and exceptions.

See how AI talks about your brand

Enter your domain to get a free AI visibility report in under 60 seconds.

14-day trialCancel anytime60 second setup