Skip to content
Enterprise trust

Controls you can inspect. Claims you can verify.

AMIN is designed so regulated organisations can see who can access what, where data lives, who decided and why — and what is confirmed before any commitment.

Enterprise trust

Built for enterprise confidence.

Security, control and auditability are built into the operating model.

AMIN helps regulated organisations operate with confidence: the right controls, clear data boundaries, human accountability and a complete, traceable audit trail.

  1. IdentityVerified people and entities
  2. AccessScoped and least privilege
  3. ControlPolicies and approvals
  4. EvidenceComplete and traceable records
  5. AuditAlways ready for review
01

Security & Access Control

The right people have the right access, with visibility and control.

  • Role-based permissions per tenant
  • OTP-verified Client Portal access
  • Role-scoped review and approval
02

Data & Privacy

Keep client data scoped, protected and under your control.

  • Tenant isolation with row-level security
  • Documents encrypted in transit and at rest
  • Hosting and residency agreed in scoping
03

Governance & Compliance

Run work in line with your policies and regulatory obligations.

  • Governed workflows with clear ownership
  • Approval controls and human accountability
  • Record keeping and reporting outputs
04

Audit & Assurance

Every decision, action and change is recorded and ready for review.

  • Complete, traceable audit timeline
  • Sealed evidence bundles (JSON or PDF)
  • Expiry and renewal alerts
  • Controlled accessRight people. Right information.
  • Clear data boundariesYour data. Under your control.
  • Human accountabilityEvery decision has an owner.
  • Traceable evidenceComplete context, always.
  • Review-ready recordsPrepared for regulators and audit.
Controls & boundaries

What is in place today — and what we agree with you.

We separate what the product does now from what is confirmed during enterprise scoping. No certifications or approvals are implied.

01

Security & Access Control

The right people have the right access, with visibility and control.

In place today
  • Separate staff and client authentication flows
  • Role-based permissions scoped to each tenant
  • One-time-code sign-in for the Client Portal
  • Role-scoped review and approval for supported workflows
Agreed in scoping
  • Single sign-on and directory provisioning requirements
  • Multi-factor authentication policy for staff users
  • Access review cadence and administration model
02

Data & Privacy

Keep client data scoped, protected and under your control.

In place today
  • Tenant isolation through application guards and database row-level security
  • Documents encrypted at rest in storage
  • Encrypted connections (TLS) for data in transit
  • Client Portal users see only their own records
Agreed in scoping
  • Hosting provider and data residency
  • Retention periods and deletion requirements
  • Customer-specific data processing terms
03

Governance & Compliance

Run work in line with your policies and regulatory obligations.

In place today
  • Cases with owners, tasks and permissioned states
  • Human decision gates for supported workflows
  • Escalation to Compliance Manager or MLRO
  • Obligations and follow-ups linked to the client record
Agreed in scoping
  • Mapping of your policies and obligations
  • Approval matrices for your organisation
  • Regulatory content and coverage
04

Audit & Assurance

Every decision, action and change is recorded and ready for review.

In place today
  • Audit timeline with actor, entity and correlation context
  • Sealed evidence bundles exportable as JSON or PDF
  • Decision rationale retained with the record
  • Expiry and renewal tracking
Agreed in scoping
  • Reporting outputs required by your oversight functions
  • Evidence retention and export routines
  • Independent assessment and assurance requests
Deployment

Tenant-isolated SaaS, scoped with you.

The currently evidenced deployment model is tenant-isolated SaaS. Hosting, residency, provider and institutional control requirements are confirmed during enterprise scoping — before any availability commitment.

  • Tenant isolation with row-level security
  • Separate staff and client access surfaces
  • Residency and hosting agreed in scoping
  • No implied certifications or regulatory approvals
Get started

Bring your security and governance questions.

We will review controls, boundaries and deployment requirements with your technical and compliance teams.

  • Tailored to your organisation
  • Focused on your use cases
  • Synthetic data — no client data needed