Your context stays yours
Keep company knowledge, workflows, standards, and IP in a governed operating layer.
Security + trust
Attested controls for the Security category. Type I covers design at a point in time; Type II covers design and operating effectiveness.
Super Amplify Services
Security
Johanson Group LLP

Security category assurance
Security, privacy, and assurance
Keep company knowledge, workflows, standards, and IP in a governed operating layer.
Use the right model or provider without losing the business logic around your work.
Connect people, agents, and systems with permissions, review points, and activity signals.
Security in practice
Explore how Super Amplify protects company context and intellectual property while connecting people, AI, agents, workflows, and systems.
Passwords, API keys, and sensitive configuration are encrypted at rest with AES-256. HTTPS/TLS 1.3 protects data in transit.
Customer data, context, capabilities, and activity stay scoped to the authorized company and user, keeping customer environments separated.
Role-aware access, company membership, administrator controls, and MFA protect accounts and workspaces.
Credentials are encrypted, kept behind server controls, and brokered only to approved actions.
Agents, workflows, integrations, and connected tools operate within explicit permissions and review points.
Access, runs, approvals, outputs, and connected actions create reviewable operational signals.
Infrastructure boundary. Cloud providers supply underlying hosting controls. AWS is identified as a subservice organization in the SOC 2 report; customer controls still apply to authorized users and credentials.
Super Amplify operates one security and AI governance program mapped across the standards customers use, with completed SOC 2 Type I and Type II attestations for the Security category. Recurring third-party review, control testing, and evidence updates continue by framework, scope, and customer deployment.
Security category for Super Amplify Services, supported by the full report, management assertion, control tests, and evidence.
Super Amplify Services
Security
Johanson Group LLP
Security category attestation for Super Amplify Services at a point in time. It does not provide an opinion on operating effectiveness over a period.
Super Amplify builds on its SOC 2 control foundation and maps the program to the frameworks customers use, including the AI management system requirements of ISO/IEC 42001. Each path has its own scope, evidence requirements, and independent review process.
Administrative, physical, and technical safeguards for applicable health data.
Encryption, company-scoped isolation, least-privilege access, MFA, audit-ready activity, and governed integrations form the control foundation for healthcare deployments.
Confirm applicability and BAA scope, document the service boundary, and validate safeguards through customer or independent assessment as required.
Risk-based assurance across security, privacy, and responsible AI governance.
SOC 2 evidence discipline, risk management, policy governance, access controls, vulnerability management, and secure development provide a foundation for a scoped HITRUST CSF assessment.
Select the applicable assessment type and scope, then engage an authorized external assessor for validation and certification review.
Cloud-service boundary, impact level, inherited controls, authorization, and continuous monitoring.
Encryption, data isolation, least privilege, change management, logging, vulnerability management, and incident response support a scoped federal offering.
Define the offering and boundary, map controls, engage a recognized third-party assessment organization, complete the assessment, and pursue agency authorization.
Internal controls over financial reporting, supported by relevant IT general controls.
Role-based access, change management, audit trails, system availability, evidence ownership, and review workflows support finance and audit diligence.
Confirm ICFR scope with finance leadership, test relevant ITGCs, and coordinate with independent financial auditors.
A risk-based information security management system and continual improvement.
Security governance, risk assessment, control ownership, evidence management, and recurring review are being formalized into the ISMS.
Finalize scope, risk treatment, Statement of Applicability, and management review, then complete an independent certification audit.
An AI management system for responsible development, provision, use, and continual improvement of AI.
AI use-case review, human oversight, accountability, safety, security, privacy, transparency, fairness, and reliability are built into the governance program and product lifecycle.
Define the AI management system scope, document AI risks and objectives, measure control performance, and complete an independent certification audit.
Evidence standard. Completed attestations are labeled clearly. Certifications, authorizations, and framework-specific conclusions are published only after the applicable scope, evidence, and independent review are complete.
Review risk, AI use cases, control performance, policy, scanning, and remediation.
Maintain recurring third-party review of applicable controls, including SOC 2 reporting, penetration testing, and framework-specific assessments as scope matures.
Review secure development, responsible AI, control changes, and customer communications.
Full report, management assertion, control tests, and supporting evidence.
Independent attestation of Security control design at a point in time.
Security questionnaires, data flows, provider boundaries, and customer-specific controls.
Passwords, API keys, and sensitive configuration are encrypted at rest with AES-256. HTTPS/TLS 1.3 protects data in transit.
Company, workspace, user, and capability access is resolved against authorized context so customer data and connected actions stay within the right boundary.
Provider credentials stay server-side and are brokered to approved actions. Raw secrets are not placed in run metadata or returned to the client.
Both reports cover the Security category for Super Amplify Services. Type I attests to control design at a point in time; Type II also covers operating effectiveness over the audited reporting period.
Super Amplify maps its security and AI governance program to the standards customers use, including HIPAA, HITRUST, FedRAMP, SOX, ISO/IEC 27001, and ISO/IEC 42001. Formal attestations, certifications, and authorizations are communicated by scope and evidence.
Yes. The restricted-use reports and related evidence are shared through an approved customer assurance process.