Which subprocessors does amaise use?
amaise works with the following subprocessors:
AI processing:
Microsoft Azure OpenAI — LLM inference. Regional data processing (EU: Switzerland North/DataZoneStandard, US: East US/DataZoneStandard, CH: Switzerland North exclusive). Contractually no training on customer data. Abuse monitoring is disabled for DataZoneStandard and Switzerland North deployments — no caching of prompts or completions. ISO 27001, SOC 2.
Google Document AI — OCR processing. Regional endpoints: EU endpoint for EU customers, Switzerland deployment for CH customers, US endpoint for US customers. Data is not retained. ISO 27001, SOC 2.
Infrastructure:
AWS — All data storage and compute. Regional accounts (Frankfurt, Zurich, Ohio). ISO 27001, SOC 1/2/3, CSA STAR, PCI DSS.
Auth0 (Okta) (US) — Identity and authentication. Processes user login data and authentication events, no customer document content. SOC 2. GDPR SCCs.
Security and compliance:
Snyk (US/EU) — Software composition analysis (dependency analysis). No access to source code or customer data. ISO 27001.
Scrut (IN) — Compliance platform for ISMS management (ISO 27001, SOC 2 lifecycle). No access to customer data — processes only infrastructure metadata and device compliance data. The data processed by Scrut contains no information that could identify individual insured persons or their cases. SOC 2. Transfer secured by SCCs.
Monitoring and operations:
BetterStack (EU) — Availability monitoring. No access to customer data.
Sentry (US) — Error tracking with automatic PII scrubbing. No customer document content. SCCs.
Mixpanel (US) — Product analytics (usage behavior). No customer data, no PII. SCCs.
Twilio (US) — SMS delivery for MFA. No customer data. SCCs.
Art. 321 Swiss Criminal Code (professional secrecy): For Swiss customers whose data is subject to professional secrecy, amaise contractually ensures that confidentiality obligations are enforced throughout the entire subprocessor chain. Core processing (documents, database) remains exclusively in Switzerland. AI processing is done via Azure OpenAI Switzerland North with abuse monitoring disabled. Supporting US services do not process customer document content and have no access to Art. 321-protected data.
Changes to the subprocessor list are communicated to customers in advance, with the right to object under GDPR Art. 28. Transfer Impact Assessments (TIA) have been conducted and documented for all US-based subprocessors.
