SCROLL FOR MORE

Your AI does the work.
You keep the proof.

Safe, accountable AI on the work that matters. If legal, risk or your regulator has said no to AI on real work until now, this is what turns it into a yes. When a copilot, a chat tool or an agent goes to email a customer file, release a payment or change production, Athena decides what it may see, stops it for a named person where it matters, and seals what happened into a record your auditor checks on their own laptop, without trusting us or the AI.

offline verifier
 █████  ████████ ██   ██ ███████ ███    ██  █████ 
██   ██    ██    ██   ██ ██      ████   ██ ██   ██
███████    ██    ███████ █████   ██ ██  ██ ███████
██   ██    ██    ██   ██ ██      ██  ██ ██ ██   ██
██   ██    ██    ██   ██ ███████ ██   ████ ██   ██
$ pip install aegis-verifier
$ aegis-attest verify evidence.mtac
reading sealed record...
checking post-quantum signature...
recomputing canonical digest (RFC-8785)...
VERIFIED OK
# run it on our evidence. flip one byte and it fails. no network. no trust in us.
>
Evidence mapped to the regimes that bite
<
[n.
01
/
11
]
> why athena

/ AI is learning to act.
Nobody can prove what it did.
/

Book a demo

Athena is the flight recorder for AI.

When AI runs the business, someone has to prove it did only what it was allowed to. Athena is how.

For two years AI answered questions. Now it moves money, changes records, sends the email, files the report, whether that is a copilot, a chat tool or an agent. The action happens inside a system and gets logged, if at all, in a format the vendor controls. So when the regulator, the board or a client asks the obvious question, show me exactly what your AI did and who authorised it, there is no answer anyone outside the company can trust. Every task you hand to AI widens that gap.

Athena closes it. Proof of what your AI did and who authorised it, that anyone can verify for themselves, offline, without trusting us. The exact action a person approved is bound to the exact action the AI took. The record is sealed, so any change to it shows. Your auditor, your regulator or your client checks it on their own machine with a free tool, and never has to take your word for anything.

What Athena does is simple to describe. A copilot goes to email a customer file to a supplier. Athena reads what is in the file and strips what must not leave. Because sending it is a consequential action, it stops and waits for the named person who has to approve it. When they approve, that approval and the exact email that went out are sealed together into one record. Your auditor opens that record on their own laptop and checks it with a free tool. A flight recorder, but for AI.

No single AI model wins forever, so Athena sits above the model, not inside it. It governs whatever your teams use today and whatever they switch to next, from a copilot to an autonomous agent. And it is priced per company, not per seat, because the risk scales with how much your AI does, not how many people you employ.

[n.
02
/
11
]
> why now

/ The rules are not coming.
They are here.
/

Regulators now ask for a real record of what automated systems do, and the dates are on the calendar. The firms that can prove their AI is accountable will deploy it where it matters most. The ones that cannot will keep it in the sandbox.

DORA, in force since 17 January 2025
EU financial entities must evidence how they manage ICT risk and the third parties, including AI, that touch it.
ECB, 31 October 2026
Letter SSM-2026-0301 asks every significant bank for a board-owned action plan on AI-driven cyber threats, due to its supervisory team by this date.
NIS2, transposed from October 2024
Essential and important entities across the EU must show how they manage and report cyber risk, with management held accountable.
GDPR, since 2018
Automated decisions about people need a record, a reason and a human who can step in. Article 22 has not changed; what AI does has.
[n.
03
/
11
]
> The problem

/ A log tells you what happened.
It can't prove a human approved it.
/

Book a demo
Where it goes wrong today
// 01
Your AI reads more than it should.
A marketing agent with a Drive connector can open the payroll folder. Keyword filters see no card number, so nothing stops it and nothing records it.
// 02
One person’s access leaks into another’s session.
A shared agent session carries one user’s token or context into another user’s conversation, and nothing in the model knows it should not.
// 03
What ran is not what was approved.
A human approved one thing and the agent executed another. The log, written afterwards, is only as honest as the agent.
// 04
The auditor asks who approved the payment.
The answer is a Slack thread, a screenshot and someone’s memory. None of it verifies, and none of it survives the person leaving.

Screenshots and CSVs are claims written by the party being audited. Athena replaces them with a record that proves itself.

What we can put a number on
97% vs 3%
Our score for spotting confidential business language, against the standard open-source tools, Presidio and GLiNER. On your own hardware, with no cloud, we score 89%.
400 MB
Prompt-injection detector that matches a 70 billion parameter cloud model, 97% against 97%, running offline.
5
Provisional patent filings on the binding method, patent-pending. The evidence format is an open IETF Internet-Draft.
31 Oct 2026
The ECB’s AI-cyber action plan deadline for supervised banks. DORA has been in force since January 2025.
WHO
authorised it
WHAT
it did
WHICH
data it touched
OFFLINE
anyone can check
[n.
04
/
11
]
> under the hood
YOUR DATAfiles · records · prompts
inspect
ATHENA DATA CONTROLallow · redact · block
release
MODEL OR AGENTsees only what you allow
PIIredactedsecretblockedboundarykept
AGENT PROPOSEStransfer €12,400 to vendor
hold
HUMAN IN COMMANDapproved by r.burls · on behalf of: finance
bind
ACTION RUNSexactly what was approved
approved= ranauthorityrecordeddriftrejected
DECISIONfrom all three modules
canonicalise · RFC 8785
SEALED RECORDML-DSA-65 signature · FIPS 204
hand over
OFFLINE VERIFIERVERIFIED OK · no network · no trust in us
one byte offREJECTEDvendornot neededkeysyours

/ How it is built.
Three parts, one record.
/

In the path, not in your stack
Athena runs as a proxy and as a hook around the calls your AI already makes. Your models, tools and agent frameworks stay as they are.
MODEL APIS
MCP TOOL CALLS
AGENT HOOKS
HTTPS PROXY
CLI
SDK
WEBHOOKS
MODEL APIS
MCP TOOL CALLS
AGENT HOOKS
HTTPS PROXY
CLI
SDK
WEBHOOKS
MODEL APIS
MCP TOOL CALLS
AGENT HOOKS
HTTPS PROXY
CLI
SDK
WEBHOOKS
MODEL APIS
MCP TOOL CALLS
AGENT HOOKS
HTTPS PROXY
CLI
SDK
WEBHOOKS
MODEL APIS
MCP TOOL CALLS
AGENT HOOKS
HTTPS PROXY
CLI
SDK
WEBHOOKS
MODEL APIS
MCP TOOL CALLS
AGENT HOOKS
HTTPS PROXY
CLI
SDK
WEBHOOKS
A human in command
Approvals sit where you set them. Nothing changes for the people doing the work until an action needs a person.
One sealed record
Every decision from all three modules lands in one record. Anyone can check it offline, years later, without asking us.
[n.
05
/
11
]
> How It Works

/ From the action
to proof anyone can check.
/

Book a demo
// 001
Athena sits at the boundaries between your AI and the data, tools and systems it uses.
Sit at the control points
icon pixelicon
// 002
Decide what data can reach which model, and stop consequential actions for a named person.
Control what it sees and does
icon pixelicon
// 003
The action that runs is bound to the one a person approved, and sealed into one record, so any change to it shows.
Bind and seal
icon pixelicon
// 004
An auditor, regulator or insurer checks the record with no network and no trust in us.
Verify offline
icon pixelicon
// 001
// 002
// 003
// 004
icon pixel
Sit at the control points
Athena sits at the boundaries between your AI and the data, tools and systems it uses.
// 001
// 002
// 003
// 004
icon pixel
Control what it sees and does
Decide what data can reach which model, and stop consequential actions for a named person.
// 001
// 002
// 003
// 004
icon pixel
Bind and seal
The action that runs is bound to the one a person approved, and sealed into one record, so any change to it shows.
// 001
// 002
// 003
// 004
icon pixel
Verify offline
An auditor, regulator or insurer checks the record with no network and no trust in us.
[n.
06
/
11
]
> installation
athena
 █████  ████████ ██   ██ ███████ ███    ██  █████ 
██   ██    ██    ██   ██ ██      ████   ██ ██   ██
███████    ██    ███████ █████   ██ ██  ██ ███████
██   ██    ██    ██   ██ ██      ██  ██ ██ ██   ██
██   ██    ██    ██   ██ ███████ ██   ████ ██   ██
$ aegis-attest verify evidence.mtac --offline
reading sealed record...
checking post-quantum signature...
recomputing canonical digest (RFC-8785)...
● VERIFIED OK
# a single tampered byte returns REJECTED
athena
 █████  ████████ ██   ██ ███████ ███    ██  █████ 
██   ██    ██    ██   ██ ██      ████   ██ ██   ██
███████    ██    ███████ █████   ██ ██  ██ ███████
██   ██    ██    ██   ██ ██      ██  ██ ██ ██   ██
██   ██    ██    ██   ██ ███████ ██   ████ ██   ██
$ aegis-attest verify evidence.mtac --offline
reading sealed record...
checking post-quantum signature...
recomputing canonical digest (RFC-8785)...
● VERIFIED OK
# a single tampered byte returns REJECTED
athena
 █████  ████████ ██   ██ ███████ ███    ██  █████ 
██   ██    ██    ██   ██ ██      ████   ██ ██   ██
███████    ██    ███████ █████   ██ ██  ██ ███████
██   ██    ██    ██   ██ ██      ██  ██ ██ ██   ██
██   ██    ██    ██   ██ ███████ ██   ████ ██   ██
$ aegis-attest verify evidence.mtac --offline
reading sealed record...
checking post-quantum signature...
recomputing canonical digest (RFC-8785)...
● VERIFIED OK
# a single tampered byte returns REJECTED

/ Check it yourself.
Without trusting us.
/

Book a demo
Independent offline verifier
An auditor checks the evidence on a laptop with the cable pulled. Verification never needs our servers.
athena
 █████  ████████ ██   ██ ███████ ███    ██  █████ 
██   ██    ██    ██   ██ ██      ████   ██ ██   ██
███████    ██    ███████ █████   ██ ██  ██ ███████
██   ██    ██    ██   ██ ██      ██  ██ ██ ██   ██
██   ██    ██    ██   ██ ███████ ██   ████ ██   ██
$ aegis-attest verify evidence.mtac --offline
reading sealed record...
checking post-quantum signature...
recomputing canonical digest (RFC-8785)...
● VERIFIED OK
# a single tampered byte returns REJECTED
Post-quantum sealed record
The record is sealed so any change is detectable, including by us. Athena does not approve its own evidence.
athena
 █████  ████████ ██   ██ ███████ ███    ██  █████ 
██   ██    ██    ██   ██ ██      ████   ██ ██   ██
███████    ██    ███████ █████   ██ ██  ██ ███████
██   ██    ██    ██   ██ ██      ██  ██ ██ ██   ██
██   ██    ██    ██   ██ ███████ ██   ████ ██   ██
$ aegis-attest verify evidence.mtac --offline
reading sealed record...
checking post-quantum signature...
recomputing canonical digest (RFC-8785)...
● VERIFIED OK
# a single tampered byte returns REJECTED
Rejects on a tampered byte
The verifier returns a clear pass, and rejects on a single tampered byte.
athena
 █████  ████████ ██   ██ ███████ ███    ██  █████ 
██   ██    ██    ██   ██ ██      ████   ██ ██   ██
███████    ██    ███████ █████   ██ ██  ██ ███████
██   ██    ██    ██   ██ ██      ██  ██ ██ ██   ██
██   ██    ██    ██   ██ ███████ ██   ████ ██   ██
$ aegis-attest verify evidence.mtac --offline
reading sealed record...
checking post-quantum signature...
recomputing canonical digest (RFC-8785)...
● VERIFIED OK
# a single tampered byte returns REJECTED
[n.
08
/
11
]
> Pricing

/ Pricing that scales
with your organisation.
/

From €500 a month for an organisation of up to 25 people, then by headcount band. Enterprise is a custom agreement. All three modules, always, and never per seat.

See pricing
[n.
09
/
11
]
> Deployment

/ Built in the EU.
Verifiable offline.
/

Book a demo

Where regulated buyers need it: a dedicated EU deployment, evidence you verify offline, and keys that stay yours.

EU-sovereign deployment
Run Athena in an EU region or on your own infrastructure. Data and records stay inside the boundary you set.
Offline-verifiable evidence
Every record carries a post-quantum signature. A free verifier on a laptop checks it with no network and no call to us.
You keep the keys
Signing keys are generated and held on your side. Nothing we operate can produce a record in your name.
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
Fixed-scope pilot

/ Start with a fixed-scope pilot.
Prove it on your own workflow.
/

Four weeks, one workflow you could not put AI on before, all three modules. You leave with AI running on real work and sealed records your own auditor can verify, whether or not you continue.

Book a demo
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE