Security + trust

Own your intelligence.Protect your advantage.

Super Amplify gives your company a governed intelligence layer for context, agents, workflows, and connected systems—while protecting the data and intellectual property that make your business unique.
SOC 2 Type I attestedSOC 2 Type II attestedEncryptionData isolationMFA + accessAudit-ready
Verified foundation

Independent assurance

SOC 2 Type I + Type II

Attested controls for the Security category. Type I covers design at a point in time; Type II covers design and operating effectiveness.

Scope

Super Amplify Services

Category

Security

Service auditor

Johanson Group LLP

AICPA SOC for Service Organizations seal

AICPA SOC framework

Security category assurance

Super Amplify Trust Center

Security, privacy, and assurance

Security by design

Protect the work that makes you different.

Super Amplify connects company context, AI models, agents, workflows, and integrations in one governed operating layer—so your data and IP stay useful without losing control.

Your context stays yours

Keep company knowledge, workflows, standards, and IP in a governed operating layer.

Your models can change

Use the right model or provider without losing the business logic around your work.

Your actions stay accountable

Connect people, agents, and systems with permissions, review points, and activity signals.

Security in practice

See how trust becomes part of the operating layer.

Explore how Super Amplify protects company context and intellectual property while connecting people, AI, agents, workflows, and systems.

1:19 · 1080p · Sound on
Press play to explore Super Amplify security and trust. Sound is optional until you are ready.

Controls

Concrete protection for everyday AI.

The controls are close to the work: protect the data, limit access, control actions, and keep the important activity reviewable.
At rest + in transit

Encryption

Passwords, API keys, and sensitive configuration are encrypted at rest with AES-256. HTTPS/TLS 1.3 protects data in transit.

Company-scoped access

Data isolation

Customer data, context, capabilities, and activity stay scoped to the authorized company and user, keeping customer environments separated.

People + permissions

Identity and MFA

Role-aware access, company membership, administrator controls, and MFA protect accounts and workspaces.

Provider access

Server-side secrets

Credentials are encrypted, kept behind server controls, and brokered only to approved actions.

Agents + integrations

Controlled actions

Agents, workflows, integrations, and connected tools operate within explicit permissions and review points.

Evidence + accountability

Audit-ready activity

Access, runs, approvals, outputs, and connected actions create reviewable operational signals.

Infrastructure boundary. Cloud providers supply underlying hosting controls. AWS is identified as a subservice organization in the SOC 2 report; customer controls still apply to authorized users and credentials.

Independent assurance

Attested foundations.

Super Amplify operates one security and AI governance program mapped across the standards customers use, with completed SOC 2 Type I and Type II attestations for the Security category. Recurring third-party review, control testing, and evidence updates continue by framework, scope, and customer deployment.

AttestedSOC 2 Type II

Design + operating effectiveness.

Security category for Super Amplify Services, supported by the full report, management assertion, control tests, and evidence.

Scope

Super Amplify Services

Category

Security

Service auditor

Johanson Group LLP

AttestedSOC 2 Type I

Design assessed.

Security category attestation for Super Amplify Services at a point in time. It does not provide an opinion on operating effectiveness over a period.

Super Amplify ServicesSecurity category

Standards coverage

One control program. Framework-specific evidence.

Super Amplify builds on its SOC 2 control foundation and maps the program to the frameworks customers use, including the AI management system requirements of ISO/IEC 42001. Each path has its own scope, evidence requirements, and independent review process.

HIPAA

HIPAA-ready controls

Control focus

Administrative, physical, and technical safeguards for applicable health data.

Super Amplify posture

Encryption, company-scoped isolation, least-privilege access, MFA, audit-ready activity, and governed integrations form the control foundation for healthcare deployments.

Independent path

Confirm applicability and BAA scope, document the service boundary, and validate safeguards through customer or independent assessment as required.

HITRUST

Assessment path

Control focus

Risk-based assurance across security, privacy, and responsible AI governance.

Super Amplify posture

SOC 2 evidence discipline, risk management, policy governance, access controls, vulnerability management, and secure development provide a foundation for a scoped HITRUST CSF assessment.

Independent path

Select the applicable assessment type and scope, then engage an authorized external assessor for validation and certification review.

FedRAMP

Federal cloud path

Control focus

Cloud-service boundary, impact level, inherited controls, authorization, and continuous monitoring.

Super Amplify posture

Encryption, data isolation, least privilege, change management, logging, vulnerability management, and incident response support a scoped federal offering.

Independent path

Define the offering and boundary, map controls, engage a recognized third-party assessment organization, complete the assessment, and pursue agency authorization.

SOX

Control alignment

Control focus

Internal controls over financial reporting, supported by relevant IT general controls.

Super Amplify posture

Role-based access, change management, audit trails, system availability, evidence ownership, and review workflows support finance and audit diligence.

Independent path

Confirm ICFR scope with finance leadership, test relevant ITGCs, and coordinate with independent financial auditors.

ISO/IEC 27001

ISMS readiness

Control focus

A risk-based information security management system and continual improvement.

Super Amplify posture

Security governance, risk assessment, control ownership, evidence management, and recurring review are being formalized into the ISMS.

Independent path

Finalize scope, risk treatment, Statement of Applicability, and management review, then complete an independent certification audit.

ISO/IEC 42001

AIMS readiness

Control focus

An AI management system for responsible development, provision, use, and continual improvement of AI.

Super Amplify posture

AI use-case review, human oversight, accountability, safety, security, privacy, transparency, fairness, and reliability are built into the governance program and product lifecycle.

Independent path

Define the AI management system scope, document AI risks and objectives, measure control performance, and complete an independent certification audit.

Evidence standard. Completed attestations are labeled clearly. Certifications, authorizations, and framework-specific conclusions are published only after the applicable scope, evidence, and independent review are complete.

Quarterly

Governance + vulnerability

Review risk, AI use cases, control performance, policy, scanning, and remediation.

Regularly

Independent review

Maintain recurring third-party review of applicable controls, including SOC 2 reporting, penetration testing, and framework-specific assessments as scope matures.

Ongoing

Secure AI operations

Review secure development, responsible AI, control changes, and customer communications.

Resources

Evidence when you need it.

Reports are restricted-use materials. Request the right evidence or start a focused security review with our team.

SOC 2 Type II report

Full report, management assertion, control tests, and supporting evidence.

SOC 2 Type I report

Independent attestation of Security control design at a point in time.

Customer assurance review

Security questionnaires, data flows, provider boundaries, and customer-specific controls.

FAQ

Short answers. Direct evidence.

How is data protected?

Passwords, API keys, and sensitive configuration are encrypted at rest with AES-256. HTTPS/TLS 1.3 protects data in transit.

How is customer data isolated?

Company, workspace, user, and capability access is resolved against authorized context so customer data and connected actions stay within the right boundary.

How are integrations and credentials handled?

Provider credentials stay server-side and are brokered to approved actions. Raw secrets are not placed in run metadata or returned to the client.

What do the SOC 2 attestations cover?

Both reports cover the Security category for Super Amplify Services. Type I attests to control design at a point in time; Type II also covers operating effectiveness over the audited reporting period.

How does the broader compliance program work?

Super Amplify maps its security and AI governance program to the standards customers use, including HIPAA, HITRUST, FedRAMP, SOX, ISO/IEC 27001, and ISO/IEC 42001. Formal attestations, certifications, and authorizations are communicated by scope and evidence.

Can customers receive the reports?

Yes. The restricted-use reports and related evidence are shared through an approved customer assurance process.

Work with Super Amplify

Use AI without giving up your edge.

Own the context, protect the data, and govern the actions that move the business forward.
Explore enterprise AI