A global professional services firm has run Athena for over a year, air-gapped, inside its own environment, with thousands of users across multiple countries and regions. By design, Athena has no access to their data.
Many AI tools are services you send your data to, and the security review becomes a question of how much you trust someone else's cloud.

Athena is software you run. Our managed cloud is one place to run it. Your own cloud account is another. So is your own data center, a fully disconnected environment, or GovCloud. It is the same product in every one.
It uses your permissions, not a copy. Athena reads who can see what from the systems you already have, person by person, as they use it. If it cannot check, it does not open the file.
Agents have their own identity. Each agent shows up in your directory like an employee. You can see what it did and switch it off the same way.
Support does not get a standing key. When we need to help, access is requested for that one issue, approved by you, time-limited, and logged.

If you run Athena in a disconnected environment, updates arrive on your schedule, not ours. And inherited permissions are only as tidy as the systems they come from: an over-shared folder is visible to an agent exactly as it is to the person using it.
SOC 2 Type II. HIPAA. We never train on your data, wherever it runs.
It's your data. These are your workflows.
The same product, inside your boundary
A global professional services firm has run Athena air-gapped inside its own cloud tenant for over a year. More than 1,000 users across multiple countries and regions. The firm's data never leaves its environment. By design, Athena Intelligence has no access to it.
Many AI tools are managed services: you send your data to someone else's cloud, and the security review becomes a question of how much you trust their infrastructure. Athena is software you run. The managed cloud is one place to deploy it. Your own VPC on GCP, Azure, or AWS is another. So is your own data center, a fully disconnected environment, or GovCloud. It is the same product in every one, with feature parity and data residency per workspace.
The runtime, Studios, Sheets, Computers, the Lakehouse, permission service, and model gateway all run inside the boundary you define. If you choose frontier model providers, API calls leave under zero-data-retention agreements. Run open-source models in-boundary and nothing crosses the edge at all.
Permissions you already have, not a copy
Athena reads who can see what from the systems you already use—Active Directory, SharePoint, your cloud IAM—person by person, as they use the platform. Files stay where they live. The cache expires automatically and is never persisted. If the permission service cannot be reached, the action does not run (fail-closed by default). An over-shared folder is visible to an agent exactly as it is to the person using it.
Each agent shows up in your directory like an employee. You can see what it did, audit its access, and switch it off the same way. Agents have their own identity, not shared credentials. A professional-services customer runs twice-yearly hard delete as a configured policy for archived engagement assets; retention controls and usage export ship with the platform.
Support does not get a standing key. When Athena needs to help, access is requested for that one issue, approved by you, time-limited to hours, and logged twice: once by Athena and once by your cluster. The professional services deployment has been penetration-tested with restrictive agent modes and zero egress across three residency regions.
What deployment looks like in practice
A Fortune 50 retailer required a vendor that could deploy the full platform inside its own VPC, and Athena passed those requirements. Athena offered the full platform—Studios, Lakehouse, Computers, agent orchestration—with no feature reduction for self-hosted installs. The professional services firm's air-gapped deployment includes the complete suite: document generation, semantic models, dashboards, workflow automation, and a BI layer that stays inside its environment.
The architecture is the same whether you run in the managed cloud or in a disconnected data center. Model calls go to 60-plus providers under zero-data-retention agreements if you choose frontier models, or to open-source models running inside your boundary if you do not. You bring your own API keys. Data residency is set per workspace: EU data stays in the EU, US data stays in the US. Zero-egress observability is available for audits.
Just-in-time support access means no vendor has standing credentials to your environment. An engineer requests access for a specific incident, you approve it, and it expires after the time window you set. Both the Athena platform and your cluster log the session. The deployment guide and architecture documentation answer the questionnaire you have sent a dozen times before. SOC 2 Type II, HIPAA compliant, and over a dozen customer security reviews passed.
Who it is for and what it replaces
Regulated organizations—audit firms, healthcare providers, financial institutions, government agencies—historically could not use frontier AI because the tools required data to leave their environment. Building in-house takes forever and has to be rebuilt every time the foundation-model stack changes. So the AI tool that passed security review was usually often the narrowest one, and a dozen point solutions grew around it.
Athena replaces that sprawl. One row in the vendor-risk spreadsheet instead of twelve. One platform with agents, workflows, a semantic layer, and BI running where your policy says it has to. The trade-off: air-gapped deployments update on your change window, not the four-minute release cadence of the managed cloud. You receive updates on your change-window schedule, not in real time. Inherited permissions are only as tidy as the systems they come from.
The posture is not that you should avoid putting data on Athena's managed cloud. It is that the platform runs where you say, with your permissions, and what you build is yours. If you leave, you retain the deployment and everything you built on it.