Shield representing security, compliance, and transparency

    We are committed to security, compliance, and transparency.

    Contact security: security@amical-ai.comTerms and conditionsPrivacy policy

    Company information

    Legal name
    9526-1061 Québec inc.
    Alias
    Amical
    Address
    200-125 Charest E, Québec, QC, G1K 3G5, Canada

    You can find us on the Québec Enterprise Register (REQ) using this NEQ.

    Compliance

    GDPR
    EU AI Act
    HIPAA
    Loi 25
    PIPEDA
    HDS

    Data supported

    • PII
    • Health data
    • Contact data

    Technical documentation

    Legal Compliance

    Amical complies with Law 25 (Quebec) and the Personal Information Protection and Electronic Documents Act (PIPEDA). It is designed according to industry best security practices aligned with SOC 2 and ISO 27001 standards, though it is not yet officially certified to date.

    Phone Servers

    • Secure hosting in Canada (AWS)
    • Isolated VPC environment
    • Multi-server redundancy via Amazon
    • Full encryption of voice data, transcriptions, and identifiers (AES-256 at rest, TLS 1.3 in transit)

    Administrator Portal

    • Secure hosting in Canada (AWS)
    • Multi-server redundancy via Amazon
    • Automated hourly backups
    • Passwordless client login via Supabase Auth (email one-time codes), with optional Google or Facebook OAuth
    • Database encryption
    • Secure transmission via TLS
    • XFRS Tokens
    • Automated testing processes
    • HTTPS requests

    No Passive Listening

    No sound is captured when the handset is hung up. By default, all calls between the AI companion and the resident are recorded, whether the call is started by the user or by the AI. Calls in which the AI is not a party (for example, a relative calling the device from their own phone) are not recorded, except with written explicit consent from the relative and the residence in specific scientific studies. Clients may disable recording in their settings; doing so removes certain features and limits Amical's ability to provide support.

    Data is maintained securely at all times.

    Subprocessors

    List version: 9 August 2026

    • Google logoGoogle
      Cloud infrastructure, Maps & Places, LLM services & authentication

      Google provides cloud infrastructure, security and data storage, Gemini LLM services used in our platform, Google Maps Platform (Maps and Places) for addresses and location data users enter or select, and Google OAuth for optional passwordless client login.

    • Meta (Facebook)
      Authentication only

      Meta (Facebook) is used solely for optional OAuth sign-in to the client portal via Supabase Auth. It is not used to process call audio, transcripts, or care data.

    • AWS logoAWS
      Cloud infrastructure & data storage

      AWS provides cloud infrastructure and secure data storage for our services.

    • Stripe logoStripe
      Payments

      Backend of payment infrastructure of applicable users.

    • Twilio logoTwilio
      Communications

      Twilio provides communication APIs used for messaging related to the Service.

    • Supabase logoSupabase
      Cloud infrastructure

      Supabase provides our database, authentication, and backend infrastructure, hosted in Canada (ca-central-1 region).

    • ElevenLabs logoElevenLabs
      Conversational voice AI

      ElevenLabs provides the conversational voice AI used for live phone conversations; at the end of each call, the transcript is transmitted to Amical and ElevenLabs retains neither the audio nor the transcript (zero retention).

    • Sentry logoSentry
      Application monitoring

      We use Sentry for application monitoring, error tracking, and, where enabled, session replay so we can diagnose failures and improve reliability. Events may include technical context and identifiers needed to investigate incidents.

    • Datadog
      Observability & monitoring

      We use Datadog as our centralized observability, logging, and alerting stack to detect anomalies and investigate incidents. Operational logs sent to Datadog can include user email addresses and other operational identifiers, but no clinical content.

    • HubSpot logoHubSpot
      CRM & marketing

      We use HubSpot for CRM, marketing automation, and support workflows, including syncing contact and deal data and handling support requests, so we can manage customer relationships and operational communications.

    • SendGrid logoSendGrid
      Transactional email

      We use SendGrid to deliver transactional emails on our behalf, such as notifications, invitations, and operational messages, to users and contacts.

    • Intuit (QuickBooks Online) logoIntuit (QuickBooks Online)
      Accounting integration

      For customers who connect QuickBooks Online, we use Intuit's services to synchronize accounting and billing-related data with their connected QuickBooks company.

    • Hologram logoHologram
      Cellular IoT connectivity

      We use Hologram only for clients who rely on cellular connectivity for their devices. It provides SIM and cellular network connectivity management for those deployments, not for all users or all devices.

    • GDMS (Grandstream)
      Device management

      The Grandstream Device Management System (GDMS) provides centralized configuration and management of the phones deployed to residences.

    Incident response

    Incident response overview

    Amical AI's incident response plan is built on a modern, highly secure, and automated cloud-native infrastructure designed for rapid detection, immediate containment, and end-to-end data integrity.

    1. Secure architecture and prevention (security by design)

    Environment isolation: Our infrastructure is hosted on AWS in Canada. Production and staging are strictly isolated in dedicated AWS accounts, with centralized access management restricted to authorized Amical personnel. Immutable infrastructure (compute): Applications run on managed Kubernetes clusters (Amazon EKS) on EC2 instances using Bottlerocket, a locked-down Linux distribution optimized for containers. Administrator SSH access is disabled by design, reducing OS-level compromise risk. Secrets management: Passwords and API keys are never stored in the codebase. Sensitive credentials are managed through AWS Secrets Manager and securely injected into containers at runtime.

    2. Detection and observability

    Proactive monitoring: Our observability, logging, and alerting stack is centralized in Datadog. We use Datadog Watchdog to automatically identify anomalies in performance, security posture, and infrastructure behavior. Automated alerting: When Watchdog or custom monitors detect anomalies (for example error spikes, unusual traffic patterns, or unexpected behavior from US-based subprocessors such as Twilio or ElevenLabs), critical alerts are immediately escalated to the engineering team for rapid investigation.

    3. Containment and recovery (GitOps approach)

    Instant deployment and rollback: Infrastructure is defined as code and versioned in GitHub. CI is managed through GitHub Actions, and CD is managed by Argo CD with Helm charts. In the event of a compromised application version or container image, Argo CD can trigger an immediate rollback to a known healthy state. Third-party flow isolation: If a vulnerability or breach is detected at a subprocessor, API communications can be rapidly disabled through centralized environment controls to isolate and contain the incident.

    4. Data integrity and backup (hybrid policy)

    Telephony data (Amazon RDS): The database used for call flows and metadata is backed up automatically once per day with a retention period of 30 days. Application administration data (Supabase): Client configuration and administration data is backed up every 5 minutes with a retention period of 7 days. Audio file storage (Amazon S3): Recordings are stored securely with an automated lifecycle policy that transitions older files to Amazon Glacier for archival. Data is retained for up to 7 years. Upon explicit client deletion request, data is purged immediately and permanently from S3 buckets.

    5. Communication and notification (SLA)

    Client transparency: In the event of a confirmed security incident affecting an operator's data, Amical AI notifies designated client administrators without undue delay, and no later than 48 hours after breach confirmation. Post-incident reporting: After resolution of a critical incident, a detailed post-mortem report is made available to the client, including root cause, potentially affected data, and corrective actions deployed through our CI/CD pipelines.

    Frequently asked questions