Amaru Demo Test· Trust Centre
All systems operational

Amaru Demo Test
Trust Centre

Certifications

Independently audited

Click any certification to see scope, auditor and how to access the underlying report.

SOC2 POWERED BY SWISE

SOC 2

Issued by AICPA · Valid through 30 Sept 2026

AICPA Trust Services Criteria audit covering security, availability, processing integrity, confidentiality and privacy. Designed for SaaS and FinTech service providers — particularly those selling to North American enterprises.

AuditorAICPALast audit1 Sept 2025Valid until30 Sept 2026
Attachments

Controls

CC6 LOGICAL AND PHYSICAL ACCESS CONTROLS

  • CC6.7 Information Transmission, Movement, and Removal
  • CC6.8 Malicious Software Prevention and Detection
  • CC6.6 Logical Access Security Measures
  • CC6.2 User Registration and Deprovisioning
  • CC6.4 Physical Access Restriction
  • CC6.3 Access Authorization and Modification
  • CC6.5 Decommissioning of Physical Assets
  • CC6.1 Logical Access Security
View 3 more CC6 LOGICAL AND PHYSICAL ACCESS CONTROLS controls

CC4 MONITORING ACTIVITIES

  • CC4.1 COSO Principle 16 (Evaluating Internal Control)
  • CC4.2 COSO Principle 17 (Communicating Internal Control Deficiencies)

P3 Privacy Criteria Related to Collection

  • P3.1 Aligned Personal Information Collection
  • P3.2 Transparent Consent Management for Personal Information

CC2 COMMUNICATION AND INFORMATION

  • CC2.3 COSO Principle 15 (External Communication)
  • CC2.1 COSO Principle 13 (Relevant and Quality Information)
  • CC2.2 COSO Principle 14 (Internal Communication of Information)

CC5 CONTROL ACTIVITIES

  • CC5.3 COSO Principle 12 (Policies and Procedures for Control Activities)
  • CC5.2 COSO Principle 11 (Technology-based Control Activities)
  • CC5.1 COSO Principle 10 (Control Activities for Risk Mitigation)

CC3 RISK ASSESSMENT

  • CC3.4 COSO Principle 9 (Identification of Changes Impacting Internal Control)
  • CC3.2 COSO Principle 7 (Risk Identification and Assessment)
  • CC3.1 COSO Principle 6 (Clearly Defined Objectives)
  • CC3.3 COSO Principle 8 (Fraud Risk Assessment)

PI1 Additonal Criteria for Processing Integrity

  • PI1.5 Information Storage and Retention Controls
  • PI1.1 Information Quality and Communication
  • PI1.4 System Output Controls
  • PI1.2 System Input Controls
  • PI1.3 System Processing Controls

A1 Additional Criteria for Availability

  • A1.1 Capacity Management
  • A1.3 Disaster Recovery Testing
  • A1.2 Environmental and Operational Resilience

CC1 CONTROL ENVIRONMENT

  • CC1.3 COSO Principle 3 (Organizational Structure and Responsibilities)
  • CC1.1 COSO Principle 1 (Integrity and Ethical Values)
  • CC1.2 COSO Principle 2 (Board Oversight and Independence)
  • CC1.4 COSO Principle 4 (Attracting, Developing, and Retaining Competent Individuals)
  • CC1.5 COSO Principle 5 (Accountability for Internal Control Responsibilities)

CC7 SYSTEM OPERATIONS

  • CC7.3 Security Incident Evaluation
  • CC7.1 Configuration and Vulnerability Monitoring
  • CC7.4 Incident Response
  • CC7.2 Anomaly Detection and Analysis
  • CC7.5 Incident Recovery

P1 Privacy Criteria Related to Notice and Communication of Objectives Related to Privacy

  • P1.1 Privacy Notice

C1 Additional Criteria for Confidentiality

  • C1.2 Disposal of Confidential Information
  • C1.1 Confidentiality of Information

P5 Privacy Criteria Related to Access

  • P5.2 Managed Data Subject Access to Personal Information
  • P5.1 Managed Data Subject Access to Personal Information

CC8 CHANGE MANAGEMENT

  • CC8.1 Managing Changes

P4 Privacy Criteria Related to Use, Retention, and Disposal

  • P4.3 Privacy-Compliant Personal Information Disposal
  • P4.2 Privacy-Aligned Personal Information Retention
  • P4.1 Purpose-Bound Personal Information Usage

CC9 RISK MITIGATION

  • CC9.1 Business Continuity and Resilience
  • CC9.2 Vendor and Partner Risk Management

P2 Privacy Criteria Related to Choice and Consent

  • P2.1 Privacy Choices and Consent:
Compliance scope

Which products are covered?

Here you'll find which certifications apply to each Amaru Demo Test product. Cells marked N/A are out of scope; In progress means an audit is currently underway.
ProductSOC 2
Web Application
Backend Appication
Resources

Documents & reports

Public documents are downloadable directly. Sensitive reports are released via an access request — usually approved within one business day.

📄
Compliance
trust-centre-description.png
192.8 KB 🌐 Public
📄
Compliance
6d4f6960-c089-475d-ab79-ea83e988cd94 (4).docx
12.1 KB 🔒 Request only
FAQ

Common questions

Answers to the questions we receive most often during security reviews.

What is cyber secuirity
Cybersecurity is the practice of protecting digital systems, networks, devices, and sensitive data from unauthorized access, cyberattacks, and digital damage
What is SOC2
SOC 2 (System and Organization Controls 2) is a voluntary compliance framework developed by the AICPA. It specifies how organizations should manage and protect customer data, serving as independent verification that a company's internal security controls are effective

Request access