SECURITY & COMPLIANCE

Security for
critical operations.

Protect sensitive data. Control access. Govern every agent.

Independently assessed security, isolated environments, and global deployment options for healthcare enterprises.

PIPEDA & PHIPA

Compliance self-attested

Canadian federal and Ontario health privacy.

Request Canada brief

GDPR

Actively maintained

European privacy controls and DPA.

Review our DPA

INDEPENDENT ASSURANCE

Independent assurance.
Ongoing accountability.

Completed audits, independent penetration testing, and validated remediation. Review the evidence in our Trust Center.

Our 2026 SOC 2 and HIPAA audit renews our existing assurance. Current issued reports are available through the Trust Center.

EXPANDING OUR ASSURANCE

Our next milestones.

Three active programs build on our completed audits and established privacy commitments.

Assessment in progress

HITRUST e1

Healthcare security

Our 2026 healthcare security assessment is underway.

Readiness in progress

ISO/IEC 27001

Information security management

Preparing our information security management system for certification.

Readiness in progress

ISO/IEC 42001

AI management

Preparing our AI management system for certification.

Discuss our compliance program

OPERATIONAL SAFEGUARDS

Control over data.
Oversight of every agent.

Define who can access data, what agents can do, and how activity is reviewed. Amigo brings these controls into the infrastructure and workflows behind patient care.

Identity & Permissions

Granular roles and scoped permissions control access. SSO, enforced MFA, and device-bound access protect our operations.

Isolated Environments

Tenant isolation, regional data boundaries, and dedicated single-tenant deployments. Encryption protects data at rest and in transit.

Auditability & Monitoring

Traceable user and agent activity, contextual audit logs, and continuous monitoring support oversight and investigation.

Agent Governance

Simulation validation, scoped tool permissions, and human escalation keep clinical agents within approved workflows.

Customer Data Protection

Our standard DPA prohibits AI training with customer data and defines retention, deletion, and subprocessor obligations.

Operational Resilience

Independent testing, tracked remediation, backup and recovery procedures, and incident response with defined customer notification obligations.

Review documented controls

CLOUD & DATA PLATFORMS

Your infrastructure.
Your deployment.

Available in the US, Canada, Australia, and GCC, with deployment support across all AWS, Microsoft Azure, and Google Cloud regions. Dedicated single-tenant deployments, Databricks, and Snowflake are also supported.

Where data is stored

Data, logs, and backups reside in the hosting locations defined for your deployment.

Where AI processes data

Model inference has separate processing locations. Regional hosting does not guarantee regional inference, and some models are unavailable in a required region.

Cloud

Amazon Web Services

Supported by Amigo

Amazon Bedrock

Regional or cross-region, depending on the model and inference profile.

Cloud

Microsoft Azure

Supported by Amigo

Azure OpenAI / Foundry

Regional, Data Zone, or Global. Model availability varies.

Cloud

Google Cloud

Supported by Amigo

Vertex AI

Regional processing depends on the model, endpoint, and feature.

Data platform

Databricks

Supported by Amigo

Foundation Model APIs / Unity Gateway

Workspace, model endpoint, and fallback locations can differ.

Data platform

Snowflake

Supported by Amigo

Snowflake Cortex AI

Inference can use other regions or clouds when cross-region processing is enabled.

We confirm storage, inference, and fallback locations for the selected models and deployment at contracting.

WORK DIRECTLY WITH AMIGO

Government and critical use cases.

Contact our team to discuss your mission, deployment architecture, and security requirements.

Contact us

SECURITY RESOURCES

Review the evidence.

On this website

Assurance status, privacy commitments, security controls, and supported deployment options.

In the Trust Center

Download our DPA and Data Protection Policy. Request audit reports, our penetration-test summary, and the Canada Regulatory Compliance Brief.

Open Trust Center

Subprocessors for your deployment

Request the current list of providers that process customer data and their processing locations for your enabled services.

Request subprocessor list

DUE DILIGENCE

Security FAQs

Looking for agreements?
View our DPA and documents

Is Amigo SOC 2 Type II audited?

Yes. Our completed audit covers the Amigo Platform across Security, Availability, and Confidentiality. The 2026 cycle is an annual renewal of existing assurance. Request the current issued report through the Trust Center.

How does Amigo demonstrate Canadian privacy compliance?

Our Canada Regulatory Compliance Brief records self-attested PIPEDA and applicable PHIPA compliance. Documented controls and our Canadian DPA addendum support those commitments. Request the brief through the Trust Center; your executed agreement defines the applicable obligations.

Can we use Amigo with protected health information?

Yes, with an executed Business Associate Agreement and the required security configuration. Our completed HIPAA assessment covers the Security and Breach Notification Rules; Privacy Rule obligations flow through the BAA.

Can all models process data in our chosen region?

No. Hosting and inference locations are separate. Model availability, provider routing, and fallback settings determine where AI processes data. We confirm the options for your deployment, including any limits on models or features.

Trusted AI infrastructure for healthcare.