Security

Security is not a feature. It is the foundation.

This page describes how AmpliFlow protects your data - in plain language. Encryption, hosting, access control and incident response. No buzzwords, just documented commitments. For binding terms, see our privacy policy and terms of service.

Last updated: 2026-09-01

How we protect your data

Security is not a promise we make in a sales meeting. It is documented, auditable, testable commitments.

EU hosting by default. Encryption at rest and in transit. Role-based access control. Incident response with clear timelines. And consultants working on ISO certification or management systems sign NDAs as part of the standard process - because your information deserves the same protection as ours.

Security at every layer

Six areas that protect your data - from infrastructure to process.

EU Hosting

Azure Sweden Central and West Europe for customer data. Hetzner Finland for website and logs. No customer data leaves the EU/EEA.

Encryption

AES-256 at rest, TLS 1.2+ in transit. Every connection to AmpliFlow is encrypted.

Access Control

Role-based access control, multi-tenant isolation and least-privilege by default.

Business Continuity

RPO under 1 hour, RTO under 4 hours. Automated backups with documented recovery targets.

Incident Response

Notification within 24 hours. Documented workflow from detection through resolution and review.

Infrastructure Certifications

Azure ISO 27001, SOC 1/2/3. See the full list at Microsoft.

Technical details

Every connection to AmpliFlow is protected with TLS 1.2+The padlock in your browser - an encrypted tunnel between you and us.. Data at rest is encrypted with AES-256Same encryption standard used by banks and governments. Practically impossible to crack. - the same standard used by banks and governments.

Access control is based on role-based access control (RBAC)You decide who sees what based on their role in the organization.. Our multi-tenantYour data is walled off from every other customer. Nobody can see your content. architecture ensures each customer's data is logically separated - nobody can see anyone else's content.

Automated backups run continuously with RPO under 1 hourAt most 1 hour of data could be lost in a serious outage. In practice, much less. andRTO under 4 hoursThe system is restored within 4 hours after a serious outage.. Backups are stored encrypted within the EU.

Our infrastructure on Azure is certified under ISO 27001International standard for information security management. Azure's infrastructure is certified. and undergoes independent SOC 2Independent audit proving security controls actually work - not just exist on paper. audits. See Azure's full certification list.

Test us

We welcome responsible security testing. Want to runpenetration testsAuthorized simulated attack to find vulnerabilities before real attackers do.against AmpliFlow? Give us a heads-up so we can coordinate.

Since AmpliFlow runs on Azure, Microsoft's penetration testing rules apply. In practice, you can test freely without special approval - but a heads-up helps us distinguish your tests from actual attacks.

Read Azure's penetration testing rules →

Contact us to coordinate →

Read our vulnerability disclosure policy →

NDA and confidentiality

Consultants working on ISO certification or management systems sign non-disclosure agreements (NDA) as part of the standard process. This is not something you need to ask for - it is included.

Need a separate NDA with AmpliFlow as a company? We arrange that. SLA is available on request. A Data Processing Agreement (DPA) is included with every subscription.

Contact us for NDA or SLA →

Frequently asked questions about security

Which chat tool do you use?
On ampliflow.com, we use LibreDesk, which we self-host with our infrastructure provider. Chat messages are processed only by AmpliFlow and our infrastructure provider, not by a separate chat provider. ampliflow.se currently uses support@ampliflow.se. The same chat setup will be added there.
Can we get an SLA?
Yes, an SLA is available on request. Contact us and we will prepare an agreement that matches your requirements.
How do you handle security incidents?
We have a documented workflow: detection, classification, remediation, notification within 24 hours and follow-up with an incident report. Every incident results in a review to prevent recurrence.
Can we perform penetration tests against AmpliFlow?
Yes. Give us a heads-up so we can coordinate. Since AmpliFlow runs on Azure, Microsoft's penetration testing rules apply - in practice, you can test freely without special approval, but a heads-up helps us distinguish your tests from actual attacks.
Where are backups stored?
Backups are stored on Azure within the EU/EEA, in the same regions as primary data (Sweden and Western Europe). Backups are encrypted with AES-256.
Can individual consultants sign NDAs?
Yes. Consultants working on ISO certification or management systems sign NDAs as part of the standard process. If you need a separate NDA with AmpliFlow as a company, we arrange that as well.

Questions about security?

Have questions about how AmpliFlow protects your data, want to coordinate penetration tests, or need an NDA - we are happy to help.

Questions about GDPR, data processing agreements, or data transfers? See our GDPR page.

Email: info@ampliflow.com

Visit our contact page →