Compliance frameworks
Our products and internal processes are designed with compliance in mind

The Amino platform is SOC 2 certified, which ensures we have the appropriate internal controls in place for secure data management and processing.

Application security measures
Amino maintains and enforces a comprehensive set of security and privacy measures

Encryption
We use enterprise-grade encryption to protect PII and PHI from unauthorized access. All communication between Amino members and our application is encrypted in transit, and databases / database backups are encrypted at rest.

Data access
To protect our customers' data, Amino practices least-access principles. Member data is only made available to approved employees with roles that require access to perform their primary job duties.

Third-party vendors
Every third-party vendor used by Amino goes through a thorough internal risk assessment process. We sign business associate agreements (BAAs) with any vendors accessing sensitive client data.

Pentesting and security scans
Amino conducts third-party pentests at least annually. In addition to regular pentesting, we also use static and dynamic scanning tools to monitor and detect vulnerabilities, and participate in a bug bounty program.