Skip to content
AMOGA
Request demo

Trust Β· Security

Security isn't an add-on. It's the architecture.

Identity, access, policy, evidence and deployment controls belong in the application model and Runtime, not in a separate checklist after release.

Request security docs View compliance β†’
Identity and accessPolicy enforcementAudit evidenceDeployment controls
Security across Shape Β· Run Β· Work

One security model follows the application and every actor inside it.

Controls begin in the application specification, are enforced by the Runtime, carried across integration events and applied to people and agents through the same enterprise context.

ShapeSpecificationRunRuntimeWorkPeople + agents
01Identitywho is acting
02Scopewhat they may see
03Authoritywhat they may change
04Evidencewhat the system retains
data protectionpolicy enforcementmonitoringrecovery

Structural security, not a feature layer.

Governance is generated, not configured

Role-based access controls, audit trails, maker-checker workflows and data access policies are produced in the same step that builds the application. No gap between launch and security.

Every action is traceable. Always.

Every access event, every change, every approval: logged from the moment the system goes live. Zero setup. Zero gaps. Full immutable audit trail.

Encryption is end-to-end, by default

Data encrypted at rest and in transit across every deployment mode: cloud, on-premise and hybrid. No configuration required. No exceptions.

Read the evidence. Verify what each report covers.

open the pdf, no form

Each tile names the standard, the firm that produced the report and the date it covers. The documents themselves are below the line: open them and check.

ISO/IEC 27001
27001:2022

Information security management system, audited against the 2022 revision.

Accorp Partners Cert Inc.
Issued December 2025 Open PDF β†’
SOC 2
Type II

Security, confidentiality and availability: design and operating effectiveness over a period.

Percilchofe CPA LLC
August 2025 – January 2026 Open PDF β†’
HIPAA
NIST SP 800-66 Rev. 2

Privacy, Security and Breach Notification rules for Protected Health Information.

Scrut Automation Inc.
Assessed February 2026 Open PDF β†’
GDPR
Regulation (EU) 2016/679

Design and controls examined against the EU General Data Protection Regulation.

Scrut Automation Inc.
Assessed February 2026 Open PDF β†’
PCI DSS
v4.0.1 Β· SAQ D
Self-assessment

Attestation of Compliance for Service Providers against the Payment Card Industry Data Security Standard.

Amoga Software Private Limited
AOC Β· SAQ D for Service Providers Open PDF β†’
VAPT
Network penetration test

External perimeter tested for gaps, vulnerabilities and misconfigurations.

Scrut Automation (Riversys Technologies)
Tested May 2026 Under NDA
India DPDP Act

Digital Personal Data Protection compliance.

MeitY Guidelines

Aligned to Indian government digital infrastructure standards.

RBI-aligned Controls

BFSI workloads with data localisation and risk management.

Built on infrastructure you can stake operations on.

Multi-region Β· always on

Primary: Azure Central India (Pune). DR: Azure South India (Chennai). Automated failover, warm standby, 24Γ—7 NOC.

Edge security Β· zero exposure

Cloudflare WAF and DDoS protection at the network edge. Private networking within Azure VNets. TLS enforced across all endpoints.

Identity Β· controlled

Enterprise SSO via SAML and OIDC. Keycloak-powered IAM with MFA and least-privilege access. Per-tenant schema-level data isolation by default.

Six layers of enterprise-grade protection.

Data encryption

AES-256 at rest, TLS 1.3 in transit. Per-tenant isolation with dedicated encryption keys.

Identity & access

RBAC down to field level. SSO/SAML, MFA enforcement, and full session audit trails.

Infrastructure security

SOC 2-compliant infrastructure. Regular VAPT, automated vulnerability scanning, 24/7 monitoring.

Compliance controls

Built-in audit logging, data retention policies, and compliance reporting across all regulations.

Incident response

Documented playbooks with defined SLAs for detection, containment, and customer notification.

Data residency

On-premises and private cloud options ensure your data never leaves your jurisdiction.

For your security team

We support customer-requested security audits.

VAPT reports, architecture documentation and compliance evidence are available for due diligence: detailed documentation, penetration test reports or compliance assessments on request, under NDA.

Request security documentation Email the security team security@amoga.io