Dispatches
Product launch

It's your data. These are your workflows.

Athena runs wherever your rules say it has to, including fully inside your own environment, so your data never has to leave.

Thousandsusers · air-gapped · over a yearA global professional services firm runs Athena fully disconnectedSend it outKeep it inUpload to vendor cloudTrust their securityHope for complianceWait for approvalMany tools require your data to leaveDeploy in your environmentYour permissions applySame productAthena runs where you saySend it out. Hope.Athena supportModel APIs (ZDR)No standing accessYOUR ENVIRONMENTAthena runtimeStudios · Sheets ·ComputersLakehouse ·DatabasePermission serviceModel gatewayAll user dataEverything runs inside; nothing crosses without explicit approval01User requestsanalysisAthena agentactivates inside …02Check sourcepermissionsReal-time inheritancefrom your systems03Read allowedfiles onlyOver-shared foldersstay over-shared04Generate outputData never leavesyour environmentSame product. Your data stays inside.Same product. Inside.Athena agentAccess financial folder for userCHECKED AGAINST THE SOURCEActive DirectorySharePointAccess granted; fileopenedIf any permissionservice cannot bereached, the actiondoes not runIf it can't check, it says no.Athena support wants toAccess runtime logs to diagnose incident#4412Requested by: Support engineerDuration: time-boxedLogs: Platform + your clusterWAITING FOR A PERSONTime-limited access granted; logged twiceApproved by your admin · expires 16:40 · no standing keyApproved by you. Logged.AthenaManaged cloudYour VPC (GCP)Your VPC (Azure)Your VPC (AWS)On-premAir-gappedGovCloudSame product in every deployment; feature parity across allDeployed on your terms.It's your data. These are yourworkflows.athenaintel.com
Fig. 01The launch in 35 seconds, from the question to the landing line: “It's your data. These are your workflows.”

A global professional services firm has run Athena for over a year, air-gapped, inside its own environment, with thousands of users across multiple countries and regions. By design, Athena has no access to their data.

Many AI tools are services you send your data to, and the security review becomes a question of how much you trust someone else's cloud.

Your Data, Your Workflows

Athena is software you run. Our managed cloud is one place to run it. Your own cloud account is another. So is your own data center, a fully disconnected environment, or GovCloud. It is the same product in every one.

It uses your permissions, not a copy. Athena reads who can see what from the systems you already have, person by person, as they use it. If it cannot check, it does not open the file.

Agents have their own identity. Each agent shows up in your directory like an employee. You can see what it did and switch it off the same way.

Support does not get a standing key. When we need to help, access is requested for that one issue, approved by you, time-limited, and logged.

Your Data, Your Workflows
What to plan for

If you run Athena in a disconnected environment, updates arrive on your schedule, not ours. And inherited permissions are only as tidy as the systems they come from: an over-shared folder is visible to an agent exactly as it is to the person using it.

SOC 2 Type II. HIPAA. We never train on your data, wherever it runs.

It's your data. These are your workflows.

The same product, inside your boundary

A global professional services firm has run Athena air-gapped inside its own cloud tenant for over a year. More than 1,000 users across multiple countries and regions. The firm's data never leaves its environment. By design, Athena Intelligence has no access to it.

Many AI tools are managed services: you send your data to someone else's cloud, and the security review becomes a question of how much you trust their infrastructure. Athena is software you run. The managed cloud is one place to deploy it. Your own VPC on GCP, Azure, or AWS is another. So is your own data center, a fully disconnected environment, or GovCloud. It is the same product in every one, with feature parity and data residency per workspace.

The runtime, Studios, Sheets, Computers, the Lakehouse, permission service, and model gateway all run inside the boundary you define. If you choose frontier model providers, API calls leave under zero-data-retention agreements. Run open-source models in-boundary and nothing crosses the edge at all.

Support (JIT, logged)Frontier models (ZDR)Updates (yourYOUR VPC · ON-PREM · AIR-GAPPED · GOVCLOUDAthena runtimeStudios · Sheets ·Computers ·LakehousePermission service(fail-closed)Model gateway (BYOkeys orin-boundary)All workspaces,data, and agentsEvery component runs inside; zero egress if you choose
Fig. 02Athena components deployed inside a customer environment with optional zero-egress configuration

Permissions you already have, not a copy

Athena reads who can see what from the systems you already use—Active Directory, SharePoint, your cloud IAM—person by person, as they use the platform. Files stay where they live. The cache expires automatically and is never persisted. If the permission service cannot be reached, the action does not run (fail-closed by default). An over-shared folder is visible to an agent exactly as it is to the person using it.

Each agent shows up in your directory like an employee. You can see what it did, audit its access, and switch it off the same way. Agents have their own identity, not shared credentials. A professional-services customer runs twice-yearly hard delete as a configured policy for archived engagement assets; retention controls and usage export ship with the platform.

Support does not get a standing key. When Athena needs to help, access is requested for that one issue, approved by you, time-limited to hours, and logged twice: once by Athena and once by your cluster. The professional services deployment has been penetration-tested with restrictive agent modes and zero egress across three residency regions.

Audit agentRead engagement files for summaryCHECKED AGAINST THE SOURCESharePointAzure ADEngagement accessFiles openedIf any check fails orcannot reach theservice, access isdenied
Fig. 03Permission checks inherit from source systems in real time; fail-closed by default

What deployment looks like in practice

A Fortune 50 retailer required a vendor that could deploy the full platform inside its own VPC, and Athena passed those requirements. Athena offered the full platform—Studios, Lakehouse, Computers, agent orchestration—with no feature reduction for self-hosted installs. The professional services firm's air-gapped deployment includes the complete suite: document generation, semantic models, dashboards, workflow automation, and a BI layer that stays inside its environment.

The architecture is the same whether you run in the managed cloud or in a disconnected data center. Model calls go to 60-plus providers under zero-data-retention agreements if you choose frontier models, or to open-source models running inside your boundary if you do not. You bring your own API keys. Data residency is set per workspace: EU data stays in the EU, US data stays in the US. Zero-egress observability is available for audits.

Just-in-time support access means no vendor has standing credentials to your environment. An engineer requests access for a specific incident, you approve it, and it expires after the time window you set. Both the Athena platform and your cluster log the session. The deployment guide and architecture documentation answer the questionnaire you have sent a dozen times before. SOC 2 Type II, HIPAA compliant, and over a dozen customer security reviews passed.

Athena support wants toAccess logs to resolve workflow timeoutissueIncident: #4412Requested duration: time-boxedAudit trail: platform log + cluster logWAITING FOR A PERSONAccess granted until 16:40; session logged twiceNo standing keys · approved by IT admin · time-bounded
Fig. 04Support access requested per incident, approved by you, and double-logged

Who it is for and what it replaces

Regulated organizations—audit firms, healthcare providers, financial institutions, government agencies—historically could not use frontier AI because the tools required data to leave their environment. Building in-house takes forever and has to be rebuilt every time the foundation-model stack changes. So the AI tool that passed security review was usually often the narrowest one, and a dozen point solutions grew around it.

Athena replaces that sprawl. One row in the vendor-risk spreadsheet instead of twelve. One platform with agents, workflows, a semantic layer, and BI running where your policy says it has to. The trade-off: air-gapped deployments update on your change window, not the four-minute release cadence of the managed cloud. You receive updates on your change-window schedule, not in real time. Inherited permissions are only as tidy as the systems they come from.

The posture is not that you should avoid putting data on Athena's managed cloud. It is that the platform runs where you say, with your permissions, and what you build is yours. If you leave, you retain the deployment and everything you built on it.

Vendor sprawlOne platformChat toolDocument AIBI copilot (approvedWorkflow builder6 more underThe one that passed did the leastAthena · full suiteDeployed in our tenantApprovedSame product as managed cloud
Fig. 05One in-environment deployment replaces a dozen managed-cloud point solutions under review
What customers say
“He wrote the entire stuff. By itself. And I was there, and I was thinking, alright. If I had to write all this stuff, I mean, I would've spent days, days, days.”
Manufacturing analyst · A global manufacturer
“I send that to the programmer and he said, alright. I read your file. I copied the section of the code because he has the right interface, and it works. Wow. Just like magic.”
Manufacturing analyst · A global manufacturer
“Digital worker, it gets spun up, it gets given access to the toolkits that it needs. It gets given access to the data that it needs. Just exists for the period it needs to exist to perform the task. And then it gets torn back down again afterwards.”
Audit lead · A global professional services firm
“I like that direction, that concept of the agent is the agent. It becomes an entity in its own right with its own ownership and its own missioning, and you get rid of the gray area and the blurry lines.”
Audit lead · A global professional services firm
“A lot of people are telling us that, oh, I sold in this package because of this info... I secured this distribution because of the selling assistance help.”
Sales enablement lead · A global CPG provider
“The performance, say, the kind of speed and latency on those APIs for creating assets, was better in [our private cloud] than it was in managed cloud.”
Audit lead · A global professional services firm
“I am not a programmer. I cannot read a line of program in SQL or anything... The only thing that I'm doing is just writing prompts.”
Manufacturing analyst · A global manufacturer
“I finally got a chance to play around with the computer asset and build out the chatbot you mentioned. It was really impressive.”
Marketing lead · An AmLaw 100 firm
“So we use the SDK, and we write that in Python, and it calls Athena majority by API. The results appear in the interface itself.”
Legal technology team · A global law firm
“You guys are functioning better because the harness is tested for a longer period of time against enterprise customers.”
Analytics lead · A Fortune 500 retailer

Verbatim from customer calls. Customers anonymized.

End to end

Audit engagement summary generated air-gapped in a global professional services firm

SURFACES INWHAT COMES INTHE PLATFORMWHAT GOES OUTDELIVERED BACKWebMobile · voiceText (SMS)EmailChromeOffice add-inMeeting botMeetingsWordPowerPointSheetsFiles · PDFsDataWorkflows (AOPs)AppsLibrarySessionsSpacesStudiosMeetingsSemantic modelsDatabaseDashboardsWordSheetsDashboardsData · APIsApps · portalsWebMobile · voiceText (SMS)EmailSlack · TeamsChromeOffice add-inMeeting botSlack · Teams1Agents2Lakehouse3PowerPoint41 INPartner requests summaryof Q3 audit findingsacross all regions forboard deck2 CHECKAudit agent checksSharePoint, Azure AD, andengagement access list;all permissions allow3 RUNAgent reads engagementfiles from every regionworkspaces; data staysin-boundary4 ANSWERDeck generated withfindings summary, regionalbreakdowns, and sourcecitations; no data egress
Fig. 06The route on the system map: Slack · Teams → Agents → Lakehouse → PowerPoint. Connectors: SharePoint, Azure AD, engagement database (all in-tenant)
What it runs on