Skip to main content

Which industry-specific frameworks does amaise comply with?

Written by amaise Support

Which industry-specific frameworks does amaise comply with?

amaise holds the following compliance frameworks and certifications:

  • ISO 27001 — Information Security Management System (certified)

  • SOC 2 Type II — Security, Availability, Confidentiality (certified)

  • NIST Cybersecurity Framework (CSF) — automated compliance rules continuously enforced

  • GDPR — EU General Data Protection Regulation (compliant)

  • nDSG — Swiss Data Protection Act (compliant)

Regulated industries:

amaise supports customers in regulated industries and actively addresses the requirements of relevant supervisory authorities:

  • FINMA (Switzerland) — Security controls are designed to support FINMA circulars (especially 2023/1 Operational Resilience, 2018/3 Outsourcing). Audit rights and BCM requirements are contractually addressed.

  • BaFin (Germany) — amaise supports VAIT/BAIT outsourcing requirements for German insurers and banks. DORA requirements (Digital Operational Resilience Act, effective January 2025) are considered as an ICT third-party service provider.

  • HIPAA (USA) — amaise meets its HIPAA obligations for US healthcare customers: Business Associate Agreements (BAAs) are signed, and protected health information (PHI) is processed under those agreements. Technical controls (encryption, access control, audit logging, breach notification) follow the HIPAA Security Rule. The systems that process PHI are covered by the scope section of our SOC 2 report, as confirmed by the SOC auditor.

amaise continuously works to achieve further certifications and regularly reviews new frameworks based on customer needs and market developments.

For specific compliance inquiries, please contact us at [email protected].

Did this answer your question?