SOC 2 Type II
Audit completed
Security, Availability, and Confidentiality.
Request SOC 2 reportSECURITY & COMPLIANCE
Protect sensitive data. Control access. Govern every agent.
Independently assessed security, isolated environments, and global deployment options for healthcare enterprises.
Audit completed
Security, Availability, and Confidentiality.
Request SOC 2 reportCompliance attested
Security and Breach Notification Rules.
Request HIPAA assessmentCompliance self-attested
Canadian federal and Ontario health privacy.
Request Canada briefActively maintained
European privacy controls and DPA.
Review our DPAINDEPENDENT ASSURANCE
Completed audits, independent penetration testing, and validated remediation. Review the evidence in our Trust Center.
Audit completed
Security, Availability, and Confidentiality.
Request SOC 2 reportCompliance attested
Security and Breach Notification Rules.
Request HIPAA assessmentRemediation validated
Independent web application and API testing.
Request executive summaryOur 2026 SOC 2 and HIPAA audit renews our existing assurance. Current issued reports are available through the Trust Center.
EXPANDING OUR ASSURANCE
Three active programs build on our completed audits and established privacy commitments.
Assessment in progress
Healthcare security
Our 2026 healthcare security assessment is underway.
Readiness in progress
Information security management
Preparing our information security management system for certification.
Readiness in progress
AI management
Preparing our AI management system for certification.
OPERATIONAL SAFEGUARDS
Define who can access data, what agents can do, and how activity is reviewed. Amigo brings these controls into the infrastructure and workflows behind patient care.
Granular roles and scoped permissions control access. SSO, enforced MFA, and device-bound access protect our operations.
Tenant isolation, regional data boundaries, and dedicated single-tenant deployments. Encryption protects data at rest and in transit.
Traceable user and agent activity, contextual audit logs, and continuous monitoring support oversight and investigation.
Simulation validation, scoped tool permissions, and human escalation keep clinical agents within approved workflows.
Our standard DPA prohibits AI training with customer data and defines retention, deletion, and subprocessor obligations.
Independent testing, tracked remediation, backup and recovery procedures, and incident response with defined customer notification obligations.
CLOUD & DATA PLATFORMS
Available in the US, Canada, Australia, and GCC, with deployment support across all AWS, Microsoft Azure, and Google Cloud regions. Dedicated single-tenant deployments, Databricks, and Snowflake are also supported.
Data, logs, and backups reside in the hosting locations defined for your deployment.
Model inference has separate processing locations. Regional hosting does not guarantee regional inference, and some models are unavailable in a required region.
Cloud
Supported by Amigo
Amazon Bedrock
Regional or cross-region, depending on the model and inference profile.
Cloud
Supported by Amigo
Azure OpenAI / Foundry
Regional, Data Zone, or Global. Model availability varies.
Cloud
Supported by Amigo
Vertex AI
Regional processing depends on the model, endpoint, and feature.
Data platform
Supported by Amigo
Foundation Model APIs / Unity Gateway
Workspace, model endpoint, and fallback locations can differ.
Data platform
Supported by Amigo
Snowflake Cortex AI
Inference can use other regions or clouds when cross-region processing is enabled.
| Cloud or data platform | Amigo support | AI processing considerations |
|---|---|---|
| Supported | Amazon Bedrock Regional or cross-region, depending on the model and inference profile. | |
| Supported | Azure OpenAI / Foundry Regional, Data Zone, or Global. Model availability varies. | |
| Supported | Vertex AI Regional processing depends on the model, endpoint, and feature. | |
| Supported | Foundation Model APIs / Unity Gateway Workspace, model endpoint, and fallback locations can differ. | |
| Supported | Snowflake Cortex AI Inference can use other regions or clouds when cross-region processing is enabled. |
We confirm storage, inference, and fallback locations for the selected models and deployment at contracting.
WORK DIRECTLY WITH AMIGO
Contact our team to discuss your mission, deployment architecture, and security requirements.
SECURITY RESOURCES
Assurance status, privacy commitments, security controls, and supported deployment options.
Download our DPA and Data Protection Policy. Request audit reports, our penetration-test summary, and the Canada Regulatory Compliance Brief.
Open Trust CenterRequest the current list of providers that process customer data and their processing locations for your enabled services.
Request subprocessor listYes. Our completed audit covers the Amigo Platform across Security, Availability, and Confidentiality. The 2026 cycle is an annual renewal of existing assurance. Request the current issued report through the Trust Center.
Our Canada Regulatory Compliance Brief records self-attested PIPEDA and applicable PHIPA compliance. Documented controls and our Canadian DPA addendum support those commitments. Request the brief through the Trust Center; your executed agreement defines the applicable obligations.
Yes, with an executed Business Associate Agreement and the required security configuration. Our completed HIPAA assessment covers the Security and Breach Notification Rules; Privacy Rule obligations flow through the BAA.
No. Hosting and inference locations are separate. Model availability, provider routing, and fallback settings determine where AI processes data. We confirm the options for your deployment, including any limits on models or features.