Protected authentication
Athena Vault uses Better Auth email/password authentication with secure session handling.
Security at Athena Vault
We use layered authentication, owner-scoped authorization, and private deployment boundaries to help keep your financial workspace secure.
How it works
Athena Vault uses Better Auth email/password authentication with secure session handling.
Sessions are stored server-side, expire automatically, and can be revoked from Account settings.
Every financial request is resolved through the authenticated user and their owner-scoped workspace.
Financial data stays inside the private application and database boundary; it is not used for public sharing.
Current capabilities
Change your password from Account settings and sign out all sessions after the update.
Review devices and revoke individual sessions or all sessions.
Email recovery is not enabled until a private mail delivery service is configured.
Authenticator-app protection is planned but is not active on this deployment.