Security at a glance. One screen.
What an IT or security reviewer usually has to read four pages to establish. Every line links to where it is explained and evidenced.
Security at a glanceWorks with MicrosoftSecurityIT & deploymentMachine identityReadings APIBusiness continuityWorking with usComplianceHow we make claims
Identity
- Microsoft Entra ID single sign-on
- MFA and Conditional Access — your policies
- Application identities for systems, not API keys
- No shared logins, no self-signup, no local passwords
Data
- Hosted in the UK — London region
- Encrypted in transit and at rest
- Daily backups with point-in-time recovery
- Restore drill rehearsed — completed in 14 minutes
- Complete export from inside the product, any day
Audit
- Append-only evidence, enforced by the database
- Every unattended machine read logged
- Membership and permission history retained
- Corrections append — nothing is overwritten
- Administrative actions audited with attribution
Access
- Least privilege — roles grant only what they name
- Integrations are read-only, with no write path
- Revocation takes effect on the next request
- Two independent kill switches for machine access
- Client secrets stay in your tenant — never held here
- Time-boxed access that lapses by itself
Amberhold is not ISO 27001 certified today. Instead we publish exactly how the platform is secured, so your own team can assess it directly — see Security for the detail behind every line above.
A question this page didn't answer?
Ask it directly — supplier questionnaires and security reviews are answered promptly, by the people who built the platform.