How is compliance continuously monitored?
amaise uses a dedicated compliance platform covering the following areas:
Certification management — managing the ISO 27001 and SOC 2 audit lifecycle
External application scans — periodic scans of cloud applications from outside (application layer)
Internal infrastructure scans — periodic scans of cloud infrastructure from inside (infrastructure layer, no data access)
Endpoint compliance monitoring — agent on all developer devices to monitor device compliance
Security training — mandatory for all team members on joining and annually
Automated evidence collection — automatic gathering of compliance evidence for audits
Additionally, automated NIST CSF compliance rules are continuously enforced in the cloud infrastructure. Quarterly security audits review access, credentials, MFA, and cloud services.
