Skip to content
New research:Dots vs. Muse for Developers

Amplifying / Trust Center

Security and compliance for agent intelligence customers.

Amplifying protects customer account data, private customer reports, and the systems that produce our benchmark intelligence. This trust center summarizes our current security posture and the materials available for review.

Security program

Active

Documented policies cover access control, data handling, incident response, vendor review, logging, endpoint security, and vulnerability management.

Compliance posture

Pre-SOC 2

Amplifying maintains CAIQ Lite v4.1.0 materials and relies on audited infrastructure providers while the formal audit program matures.

Customer data intake

By request

We do not ingest customer data unless you specifically request it.

Security contact

security@amplifying.ai

Use this address for security reviews, vulnerability reports, DPA requests, data-subject requests, and CAIQ requests.

Review materials

Documents

We share security and privacy review materials with customers and prospects under the appropriate review context. Amplifying is pre-SOC 2 and will update this page as the audit program changes.

CAIQ Lite v4.1.0

Available on request

Cloud Security Alliance CAIQ Lite response for Amplifying's current service posture.

Security program summary

Public

A plain-language summary of security controls, data handling, subprocessors, and contact paths on this page.

DPA and privacy review

Available on request

Data protection review materials and contractual privacy documentation for customer security review.

DPIA summary

Available on request

A Data Protection Impact Assessment is maintained for the current service and can be shared during review.

Controls

Security practices

These controls reflect Amplifying's current operating model: a small engineering team, managed cloud providers, and a security program designed around customer report confidentiality and controlled production access.

Data protection

Traffic uses TLS 1.2 or higher, with TLS 1.3 where supported. Data at rest is encrypted through managed providers such as Neon, Vercel, and AWS.

Access control

Administrative access follows least privilege, named accounts, provider IAM, and MFA requirements for administrative systems.

Secure development

Production changes go through pull requests, reviewer approval, CI checks, and Vercel preview review before merge.

Vulnerability management

Dependency alerts and security findings are reviewed by severity, tracked to closure, and remediated through the standard change process.

Logging and monitoring

Operational logs, error events, provider security alerts, and platform events are monitored by engineering for reliability and security response.

Incident response

A documented incident response process covers triage, containment, recovery, customer notification, and post-incident review.

Data handling

What we protect

Amplifying's customer-facing product is built around Amplifying-generated benchmark intelligence. We ingest customer data only when you specifically request it.

Account and access metadata

Amplifying stores the account, entitlement, contact, and authentication-adjacent metadata required to operate customer access.

Amplifying-generated benchmark data

Benchmark prompts, repository fixtures, runs, model responses, extracted results, and datasets are created and operated by Amplifying.

Customer reports and dashboards

Private reports and dashboards are access-controlled to the customer relationship. They may include customer-supplied data when you specifically request it.

Customer data ingestion

We do not ingest customer data unless you specifically request it. This includes customer source repositories, workspace files, and benchmark inputs or outputs.

Subprocessors

Service providers

These providers support the application and our business operations. Usage varies by service. Additional details are available on request.

ProviderServiceTerms
AnthropicAI providerLegal
AWSCloud services, including AI API accessLegal
ClerkAuthenticationLegal
CloudflareWeb infrastructure and securityLegal
CursorAI providerLegal
GitHubDevelopment tools and AI assistanceLegal
Google Cloud (GCP)Cloud services, including AI API accessLegal
Google WorkspaceProductivity and collaborationLegal
LinearProject managementLegal
Microsoft AzureCloud services, including AI API accessLegal
NeonData storageLegal
OpenAIAI providerLegal
OpenRouterAI providerLegal
PostHogAnalyticsLegal
ResendEmail deliveryLegal
SentryError monitoringLegal
SlackCommunication and collaborationLegal
StripeBilling and paymentsLegal
TailscaleSecure network accessLegal
UpstashData storageLegal
VercelHostingLegal

Security requests

Need review materials or reporting a vulnerability?

Send security questions, vulnerability reports, DPA requests, CAIQ requests, and data-subject requests to security@amplifying.ai. For vulnerability reports, include the affected URL or system, reproduction steps, impact, and any relevant logs or screenshots.