Athera/Trust
Trust
Security, plainly stated.
This page is maintained by Athera Intelligence to answer common security and privacy questions about how we work. It describes practices we apply on projects we build and operate — it is not an independent certification.
Shared responsibility
Athera builds and can operate the application layer. The underlying cloud provider (for example Cloudflare, AWS, or GCP) is responsible for infrastructure security. You, as the client, remain responsible for the data you collect, the users you invite, and any regulatory obligations specific to your business.
Practices we apply
Least-privilege access
SSO-backed identity for every environment. Production access is short-lived, logged, and reviewed quarterly.
Encryption in transit and at rest
TLS everywhere and at-rest encryption on managed databases and storage buckets we operate.
Secrets management
No secrets in code or chat. Values live in the provider's vault; access is scoped to the environment that needs them.
Dependency & code review
Every change goes through review and automated checks; dependencies are scanned continuously and patched on a schedule.
Backups & recovery
Automated daily backups with tested restore procedures for every production database we manage.
Incident response
A written runbook, an on-call rotation for retainer clients, and a customer-notification SLA for confirmed incidents.
Formal compliance
On request.
Enterprise clients often need a DPA, subprocessor list, or vendor questionnaire. We handle those on a per-engagement basis rather than publishing generic claims. Reach out and we'll share the relevant documentation for your review.
How we work
Testimonials
You work with the person building your product. No account managers, no handoffs.
Direct with the engineer
How we work
Scope and cost settled before a line of code. No hourly surprises.
Fixed price, agreed upfront
How we work
Full source, full ownership, documented handover. No lock-in.
Yours to keep
How we work