Athena

[n.
01
/
06
]
> One record

/ The flight recorder for AI.
One sealed record.
/

Athena is the flight recorder for AI: proof of what your AI did and who authorised it, that anyone can verify for themselves, offline, without trusting us. In practice: A copilot goes to email a customer file to a supplier. Athena reads what is in the file and strips what must not leave. Because sending it is a consequential action, it stops and waits for the named person who has to approve it. When they approve, that approval and the exact email that went out are sealed together into one record. Your auditor opens that record on their own laptop and checks it with a free tool. Underneath, three parts write to one record: what your AI received, what a person approved and what actually ran are one chain, never three logs joined by timing.

[n.
02
/
06
]
> Data Control

/ Data Control.
What is your AI seeing?
/

Every call from your estate to a model, agent or tool passes Data Control first. It discovers the AI your people already use, classifies what is about to leave, and applies your policy in the path: allow, redact or block. The boundary fails closed, and every crossing is written to the record.

YOUR DATAfiles · records · prompts
inspect
ATHENA DATA CONTROLallow · redact · block
release
MODEL OR AGENTsees only what you allow
PIIredactedsecretblockedboundarykept
// Shadow-AI discovery
Every model and agent call from your estate, including the ones nobody approved.
// Classification and DLP
Personal data, secrets and regulated fields identified before they leave.
// Egress boundary, fail-closed
If policy cannot be evaluated, nothing crosses.
// Redaction and masking
The model gets the task, never the identity behind it.
// Fingerprint and canary tracers
Know when your data shows up where it should not.
// Credential firewall
Keys and tokens never reach a prompt.
// Proof of what crossed
Every crossing sealed into the same record as the actions it fed.
// Data-residency proof
Evidence that data stayed in the region you chose.
[n.
03
/
06
]
> Secure Runtime

/ Secure Runtime.
What is your AI doing?
/

Consequential actions are held at one checkpoint until a named human approves them. The approval is bound to the exact action that runs, with the authority it ran under recorded as a field. If what runs drifts from what was approved, it does not run. Confinement and a kill-switch sit underneath, so a runaway agent stops in milliseconds.

AGENT PROPOSEStransfer €12,400 to vendor
hold
HUMAN IN COMMANDapproved by r.burls · on behalf of: finance
bind
ACTION RUNSexactly what was approved
approved= ranauthorityrecordeddriftrejected
// Human-approval binding
The approved action and the executed action share one hash, not a timestamp.
// On-behalf-of authority
Who the action counted against, recorded as a field in the record.
// Scope gate, fail-closed
Out of scope means it does not run, even if the agent insists.
// One tool-call checkpoint
Every consequential call passes the same gate, whatever the framework.
// Kernel-level confinement
The agent cannot reach what the policy did not open.
// Instant block and kill-switch
Stop one agent or all of them, from one place.
// Undo and rollback
A reversible record of what changed, so a bad run is not permanent.
// A sealed record of every action
Held, approved, ran, and by whose authority.
[n.
04
/
06
]
> Sovereign Compliance

/ Sovereign Compliance.
Can anyone check it?
/

Every decision from all three modules is canonicalised and signed with ML-DSA-65 (FIPS 204). The verifier runs on an auditor’s laptop with the network cable pulled and returns a clear pass or a rejection. One changed byte is rejected. The keys are yours, so nobody needs to trust Athena, or us, to accept the evidence.

DECISIONfrom all three modules
canonicalise · RFC 8785
SEALED RECORDML-DSA-65 signature · FIPS 204
verify
OFFLINE VERIFIERVERIFIED OK · no network · no trust in us
one byte offREJECTEDvendornot neededkeysyours
// Tamper-evident sealed record
Any change is detectable, including by us. Tamper-evident, never tamper-proof.
// Post-quantum sealing
ML-DSA-65 today, so a record sealed now stays checkable for years.
// Independent offline verifier
Free on PyPI (pip install aegis-verifier), runs anywhere, needs nothing from our servers.
// Evidence packs
Records bundled for an auditor or regulator, self-verifying on arrival.
// Regulation mapping (OSCAL)
Each record cross-walked to the controls it evidences.
// Honest coverage and gaps
The pack says what it does not cover, in the pack.
// Chain-of-custody and trusted time
Who held the record, and when, is part of the record.
// Retention and re-attestation
Re-seal before an algorithm ages out, without losing the chain.
[n.
05
/
06
]
> How it works

/ Four steps, in order.
None of them trusts us.
/

// 01
Sit at the control points

A proxy in front of your model APIs, a hook on your agent runtime, an SDK where you need it. No rewrite of your stack.

// 02
Control what it sees and does

Data Control filters what leaves. Secure Runtime holds consequential actions for a human. Both fail closed.

// 03
Bind and seal

The approved action, the executed action and the authority behind it are bound into one canonical, signed record.

// 04
Verify offline

Your auditor runs the verifier on their own machine. Pass or reject, with no call to us.

[n.
06
/
06
]
> Regulation

/ Mapped to the frameworks
your auditor already uses.
/

Each sealed record is cross-walked, in OSCAL, to the controls it evidences. Your auditor gets records and a machine-readable mapping, not a slide. We map evidence to controls; we do not issue a legal opinion, and we do not grant certification.

DORA
NIS2
GDPR
HIPAA
ISO 42001
ISO 27001
SOC 2
OSCAL
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
Fixed-scope pilot

/ Start with a fixed-scope pilot.
Prove it on your own workflow.
/

Four weeks, one workflow of yours, all three modules. You leave with AI running on real work and sealed records your own auditor can verify, whether or not you continue.

Book a demo
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE
//
ACCOUNTABLE
&
VERIFIABLE
//
PROVABLE
&
SEALED
//
SOVEREIGN
&
OFFLINE
//
ANSWERABLE
&
AUDITABLE