Amplifying / Trust Center
Security and compliance for agent intelligence customers.
Amplifying protects customer account data, private customer reports, and the systems that produce our benchmark intelligence. This trust center summarizes our current security posture and the materials available for review.
Security program
Active
Documented policies cover access control, data handling, incident response, vendor review, logging, endpoint security, and vulnerability management.
Compliance posture
Pre-SOC 2
Amplifying maintains CAIQ Lite v4.1.0 materials and relies on audited infrastructure providers while the formal audit program matures.
Customer data intake
Limited
The current product does not intentionally ingest customer source repositories, workspace files, benchmark prompts, inputs, or outputs.
Security contact
security@amplifying.ai
Use this address for security reviews, vulnerability reports, DPA requests, data-subject requests, and CAIQ requests.
Review materials
Documents
We share security and privacy review materials with customers and prospects under the appropriate review context. Amplifying is pre-SOC 2 and will update this page as the audit program changes.
CAIQ Lite v4.1.0
Available on requestCloud Security Alliance CAIQ Lite response for Amplifying's current service posture.
Security program summary
PublicA plain-language summary of security controls, data handling, subprocessors, and contact paths on this page.
DPA and privacy review
Available on requestData protection review materials and contractual privacy documentation for customer security review.
DPIA summary
Available on requestA Data Protection Impact Assessment is maintained for the current service and can be shared during review.
Controls
Security practices
These controls reflect Amplifying's current operating model: a small engineering team, managed cloud providers, and a security program designed around customer report confidentiality and controlled production access.
Data protection
Traffic uses TLS 1.2 or higher, with TLS 1.3 where supported. Data at rest is encrypted through managed providers such as Neon, Vercel, and AWS.
Access control
Administrative access follows least privilege, named accounts, provider IAM, and MFA requirements for administrative systems.
Secure development
Production changes go through pull requests, reviewer approval, CI checks, and Vercel preview review before merge.
Vulnerability management
Dependency alerts and security findings are reviewed by severity, tracked to closure, and remediated through the standard change process.
Logging and monitoring
Operational logs, error events, provider security alerts, and platform events are monitored by engineering for reliability and security response.
Incident response
A documented incident response process covers triage, containment, recovery, customer notification, and post-incident review.
Data handling
What we protect
Amplifying's customer-facing product is built around Amplifying-generated benchmark intelligence. The current service is intentionally scoped away from customer workspace ingestion.
Account and access metadata
Amplifying stores the account, entitlement, contact, and authentication-adjacent metadata required to operate customer access.
Amplifying-generated benchmark data
Benchmark prompts, repository fixtures, runs, model responses, extracted results, and datasets are created and operated by Amplifying.
Customer reports and dashboards
Private reports and dashboards are generated from Amplifying-created research data and access-controlled to the customer relationship.
No customer workspace ingestion
Customers do not currently upload their own source repositories, workspace files, benchmark prompts, benchmark inputs, or benchmark outputs to the product.
Subprocessors
Service providers
These subprocessors support the current Amplifying service. Each provider processes only the data needed for its role.
| Provider | Purpose | Data processed | Terms |
|---|---|---|---|
| Vercel | Application hosting, edge delivery, deployments, and serverless functions. | Request metadata, application data in transit, deployment metadata, logs, and analytics events. | Legal |
| Neon | Managed Postgres database for the Amplifying application. | Account metadata, entitlements, application records, and Amplifying-generated dashboard/report data. | Legal |
| Clerk | Authentication, identity, sessions, and account access management. | Authentication identifiers, session metadata, MFA metadata, and related account identifiers. | Legal |
| AWS | Cloud infrastructure and supporting service operations. | Operational metadata, generated artifacts, and service data required for the specific AWS-backed function. | Legal |
| GitHub | Source control, pull requests, CI/CD workflows, and security scanning. | Application source code, build logs, workflow metadata, security alerts, and repository activity. | Legal |
| Sentry | Error monitoring, diagnostics, and application health visibility. | Error events, stack traces, request/browser metadata, and related diagnostic context. | Legal |
| Resend | Operational email delivery and newsletter/contact management. | Recipient email addresses, newsletter contacts, subscription status, transactional email content, and delivery metadata. | Legal |
| PostHog | Product analytics and usage measurement. | Page views, product events, device/browser metadata, referrers, and usage analytics. | Legal |
Security requests
Need review materials or reporting a vulnerability?
Send security questions, vulnerability reports, DPA requests, CAIQ requests, and data-subject requests to security@amplifying.ai. For vulnerability reports, include the affected URL or system, reproduction steps, impact, and any relevant logs or screenshots.