Shield representing security, compliance, and transparency

    We are committed to security, compliance, and transparency.

    Contact security: security@amical-ai.comTerms and conditionsPrivacy policy
    Back to Compliance

    Controls

    • Secure authentication

      Client portal access uses passwordless authentication via Supabase Auth (email one-time codes), with optional Google or Facebook OAuth. Sessions are managed securely. Internal infrastructure access for Amical staff is separate and is not part of the client login experience.

    • Access control procedures established

      Our access control policy documents the requirements for adding, modifying, and removing user access, following the principle of least privilege.

    • Remote access encrypted

      Production systems can only be accessed remotely by authorized employees via an approved encrypted connection.

    • Role-based access control

      A role-based access control model is applied systematically, with built-in protection against privilege escalation.

    • Injection protection

      Critical database functions are configured according to industry best practices to prevent injection attacks.

    • Encryption at rest

      All stored data is encrypted at rest according to industry standards.

    • Encryption in transit

      All communications between clients and our servers are protected with TLS encryption.

    • High availability and performance

      Our infrastructure is sized and tuned to ensure stable and performant access, even during peak usage.