HomeLegalSecurity & compliance
Legal

Security & compliance

SOC 2 Type II. ISO 27001. HIPAA-ready. Region residency. Single-tenant deployments. Read on for the full story.

Compliance

SOC 2 Type II audited annually by a Big 4 firm. ISO 27001 certified. HIPAA-ready with signed BAAs for healthcare customers. GDPR + CCPA compliant. Our auditors' reports are available under NDA.

Architecture

Multi-tenant by default with full logical isolation. Enterprise customers run on single-tenant deployments with their own database, their own region, and their own Ami inference. EU + India + US regions available.

Encryption

TLS 1.3 in transit. AES-256 at rest. Customer-managed encryption keys (BYOK) available on Enterprise. Keys are never co-located with data.

Access

Zero standing access. Engineers can only access production via a break-glass procedure with audit logging. Customers can require all access to be approved by a designated security contact.

Incident response

24/7 on-call. Mean time to detect: 4 minutes. Mean time to communicate: 12 minutes. We publish post-mortems publicly within 7 days of any P0 incident.

Last updated: May 22, 2026. For questions, contact legal@amdital.com.