AthenaLegal & Transparency

Athena Beta · Evaluation Sandbox

Incident Response & Breach Notification

How to report a security problem, how we respond, and what we commit to doing if data in the Athena beta is exposed.

Version 0.1 (draft) Status Draft — pending legal review Applies to Athena beta (evaluation sandbox)
Report an incident

Contact us immediately

If you believe classified, OFFICIAL: Sensitive or PROTECTED material has been entered into Athena, tell us straight away and notify your own agency security officer in parallel. Do not wait for us.

1. What counts as an incident

2. How we respond

  1. Acknowledge — we confirm receipt of your report within 4 business hours.
  2. Contain — revoke sessions, disable affected accounts, isolate the affected host, or take the service offline if that is the safest option.
  3. Assess — establish what happened, what data was involved, whose data it was, and whether it is likely to result in serious harm.
  4. Notify — see section 3.
  5. Remediate — fix the cause, verify the fix, and confirm the codebase change ledger records exactly what was altered.
  6. Report — provide affected participants and their agencies with a written post-incident report covering cause, impact, timeline and corrective actions.

3. Notification commitments

Notifiable Data Breaches scheme

Part IIIC of the Privacy Act 1988 (Cth) establishes the Notifiable Data Breaches scheme. Where there is unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to any affected individual, and we cannot prevent that harm through remedial action, we must notify both the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable. Where we suspect an eligible data breach may have occurred, we must complete an assessment within 30 days.

A note on obligations

Whether the NDB scheme applies to Polstar Holdings Pty Ltd as a matter of law depends on turnover and other factors under the small business provisions of the Privacy Act. Our client agreements already commit us to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and we commit to complying with the notification obligations set out on this page for the Athena beta regardless of whether they are legally mandatory. We would not ask a government agency to accept a lower standard because of a turnover threshold.

What we commit to for the beta

4. Offshore incidents

Because inference runs in Czechia and some models are reached through Frontier Access in the United States, an incident may occur at a subprocessor rather than in our own systems. In that case:

5. Reporting a vulnerability

We welcome reports from security researchers and from agency security teams. Please email support@aristosai.com with enough detail to reproduce the issue.

6. Known limitations of this plan

Be aware