Amplifying / Trust Center

Security and compliance for agent intelligence customers.

Amplifying protects customer account data, private customer reports, and the systems that produce our benchmark intelligence. This trust center summarizes our current security posture and the materials available for review.

Security program

Active

Documented policies cover access control, data handling, incident response, vendor review, logging, endpoint security, and vulnerability management.

Compliance posture

Pre-SOC 2

Amplifying maintains CAIQ Lite v4.1.0 materials and relies on audited infrastructure providers while the formal audit program matures.

Customer data intake

Limited

The current product does not intentionally ingest customer source repositories, workspace files, benchmark prompts, inputs, or outputs.

Security contact

security@amplifying.ai

Use this address for security reviews, vulnerability reports, DPA requests, data-subject requests, and CAIQ requests.

Review materials

Documents

We share security and privacy review materials with customers and prospects under the appropriate review context. Amplifying is pre-SOC 2 and will update this page as the audit program changes.

CAIQ Lite v4.1.0

Available on request

Cloud Security Alliance CAIQ Lite response for Amplifying's current service posture.

Security program summary

Public

A plain-language summary of security controls, data handling, subprocessors, and contact paths on this page.

DPA and privacy review

Available on request

Data protection review materials and contractual privacy documentation for customer security review.

DPIA summary

Available on request

A Data Protection Impact Assessment is maintained for the current service and can be shared during review.

Controls

Security practices

These controls reflect Amplifying's current operating model: a small engineering team, managed cloud providers, and a security program designed around customer report confidentiality and controlled production access.

Data protection

Traffic uses TLS 1.2 or higher, with TLS 1.3 where supported. Data at rest is encrypted through managed providers such as Neon, Vercel, and AWS.

Access control

Administrative access follows least privilege, named accounts, provider IAM, and MFA requirements for administrative systems.

Secure development

Production changes go through pull requests, reviewer approval, CI checks, and Vercel preview review before merge.

Vulnerability management

Dependency alerts and security findings are reviewed by severity, tracked to closure, and remediated through the standard change process.

Logging and monitoring

Operational logs, error events, provider security alerts, and platform events are monitored by engineering for reliability and security response.

Incident response

A documented incident response process covers triage, containment, recovery, customer notification, and post-incident review.

Data handling

What we protect

Amplifying's customer-facing product is built around Amplifying-generated benchmark intelligence. The current service is intentionally scoped away from customer workspace ingestion.

Account and access metadata

Amplifying stores the account, entitlement, contact, and authentication-adjacent metadata required to operate customer access.

Amplifying-generated benchmark data

Benchmark prompts, repository fixtures, runs, model responses, extracted results, and datasets are created and operated by Amplifying.

Customer reports and dashboards

Private reports and dashboards are generated from Amplifying-created research data and access-controlled to the customer relationship.

No customer workspace ingestion

Customers do not currently upload their own source repositories, workspace files, benchmark prompts, benchmark inputs, or benchmark outputs to the product.

Subprocessors

Service providers

These subprocessors support the current Amplifying service. Each provider processes only the data needed for its role.

ProviderPurposeData processedTerms
VercelApplication hosting, edge delivery, deployments, and serverless functions.Request metadata, application data in transit, deployment metadata, logs, and analytics events.Legal
NeonManaged Postgres database for the Amplifying application.Account metadata, entitlements, application records, and Amplifying-generated dashboard/report data.Legal
ClerkAuthentication, identity, sessions, and account access management.Authentication identifiers, session metadata, MFA metadata, and related account identifiers.Legal
AWSCloud infrastructure and supporting service operations.Operational metadata, generated artifacts, and service data required for the specific AWS-backed function.Legal
GitHubSource control, pull requests, CI/CD workflows, and security scanning.Application source code, build logs, workflow metadata, security alerts, and repository activity.Legal
SentryError monitoring, diagnostics, and application health visibility.Error events, stack traces, request/browser metadata, and related diagnostic context.Legal
ResendOperational email delivery and newsletter/contact management.Recipient email addresses, newsletter contacts, subscription status, transactional email content, and delivery metadata.Legal
PostHogProduct analytics and usage measurement.Page views, product events, device/browser metadata, referrers, and usage analytics.Legal

Security requests

Need review materials or reporting a vulnerability?

Send security questions, vulnerability reports, DPA requests, CAIQ requests, and data-subject requests to security@amplifying.ai. For vulnerability reports, include the affected URL or system, reproduction steps, impact, and any relevant logs or screenshots.