Private records. Explicit boundaries.

ATH3NA uses layered authentication, authorization, database isolation and hosted payment boundaries.

Account security

Supabase authentication, verified email and server-side session validation.

Authorization

Role-based access and server-side route authorization; a hostname never grants access.

Data isolation

Row Level Security and private evidence storage separate client records.

Server secrets

Provider and payment credentials remain encrypted server-side and are not exposed to browser code.

Payments

Stripe-hosted Checkout and Customer Portal keep payment-card data outside ATH3NA.

Trading boundary

No broker-password storage, no order routing and no direct trade execution.

Audit history

Governed identity, publication, subscription and billing changes retain audit history.

Current scope

ATH3NA does not claim a security certification that has not been independently awarded.