Athera/Trust

Trust

Security, plainly stated.

This page is maintained by Athera Intelligence to answer common security and privacy questions about how we work. It describes practices we apply on projects we build and operate — it is not an independent certification.

Shared responsibility

Athera builds and can operate the application layer. The underlying cloud provider (for example Cloudflare, AWS, or GCP) is responsible for infrastructure security. You, as the client, remain responsible for the data you collect, the users you invite, and any regulatory obligations specific to your business.

Practices we apply

Least-privilege access

SSO-backed identity for every environment. Production access is short-lived, logged, and reviewed quarterly.

Encryption in transit and at rest

TLS everywhere and at-rest encryption on managed databases and storage buckets we operate.

Secrets management

No secrets in code or chat. Values live in the provider's vault; access is scoped to the environment that needs them.

Dependency & code review

Every change goes through review and automated checks; dependencies are scanned continuously and patched on a schedule.

Backups & recovery

Automated daily backups with tested restore procedures for every production database we manage.

Incident response

A written runbook, an on-call rotation for retainer clients, and a customer-notification SLA for confirmed incidents.

Formal compliance

On request.

Enterprise clients often need a DPA, subprocessor list, or vendor questionnaire. We handle those on a per-engagement basis rather than publishing generic claims. Reach out and we'll share the relevant documentation for your review.

How we work

Testimonials

You work with the person building your product. No account managers, no handoffs.

Direct with the engineer

How we work

Scope and cost settled before a line of code. No hourly surprises.

Fixed price, agreed upfront

How we work

Full source, full ownership, documented handover. No lock-in.

Yours to keep

How we work