We are committed to security, compliance, and transparency.
Controls
Secure authentication
Client portal access uses passwordless authentication via Supabase Auth (email one-time codes), with optional Google or Facebook OAuth. Sessions are managed securely. Internal infrastructure access for Amical staff is separate and is not part of the client login experience.
Access control procedures established
Our access control policy documents the requirements for adding, modifying, and removing user access, following the principle of least privilege.
Remote access encrypted
Production systems can only be accessed remotely by authorized employees via an approved encrypted connection.
Role-based access control
A role-based access control model is applied systematically, with built-in protection against privilege escalation.
Injection protection
Critical database functions are configured according to industry best practices to prevent injection attacks.
Encryption at rest
All stored data is encrypted at rest according to industry standards.
Encryption in transit
All communications between clients and our servers are protected with TLS encryption.
High availability and performance
Our infrastructure is sized and tuned to ensure stable and performant access, even during peak usage.