Which industry-specific frameworks does amaise comply with?
amaise holds the following compliance frameworks and certifications:
ISO 27001 — Information Security Management System (certified)
SOC 2 Type II — Security, Availability, Confidentiality (certified)
NIST Cybersecurity Framework (CSF) — automated compliance rules continuously enforced
GDPR — EU General Data Protection Regulation (compliant)
nDSG — Swiss Data Protection Act (compliant)
Regulated industries:
amaise supports customers in regulated industries and actively addresses the requirements of relevant supervisory authorities:
FINMA (Switzerland) — Security controls are designed to support FINMA circulars (especially 2023/1 Operational Resilience, 2018/3 Outsourcing). Audit rights and BCM requirements are contractually addressed.
BaFin (Germany) — amaise supports VAIT/BAIT outsourcing requirements for German insurers and banks. DORA requirements (Digital Operational Resilience Act, effective January 2025) are considered as an ICT third-party service provider.
HIPAA (USA) — For US healthcare customers, a Business Associate Agreement (BAA) is available. Technical controls (encryption, access control, audit logging, breach notification) are aligned with the HIPAA Security Rule.
amaise continuously works to achieve further certifications and regularly reviews new frameworks based on customer needs and market developments.
For specific compliance inquiries, please contact us at [email protected].
