Skip to main content

Which subprocessors does amaise use?

Written by amaise Support

Which subprocessors does amaise use?

amaise works with the following subprocessors:

AI processing:

  • Microsoft Azure OpenAI — LLM inference. Regional data processing in deployments restricted to the corresponding data zone (EU: EU data zone — France Central, Germany West Central, Italy North, Poland Central, Spain Central, Sweden Central, West Europe; US: US data zone — Central US, East US, East US 2, North Central US, South Central US, West US, West US 3; CH: Switzerland North exclusive). Contractually no training on customer data. Under Microsoft's terms, prompt and completion content may be retained for up to 30 days for abuse monitoring, accessible only to authorized Microsoft reviewers, and is never used to train or improve models. amaise itself logs only token counts — no prompt or completion content. ISO 27001, SOC 2.

  • Google Document AI — OCR processing for EU and US customers. Regional endpoints: EU endpoint for EU customers, US endpoint for US customers. Data is not retained. ISO 27001, SOC 2.

  • Microsoft Azure AI Document Intelligence — OCR processing for Swiss customers, hosted in Switzerland (Switzerland North). Data is not retained, no training on customer data. ISO 27001, SOC 2.

Infrastructure:

  • AWS — All data storage and compute. Regional accounts (Frankfurt, Zurich, Ohio). ISO 27001, SOC 1/2/3, CSA STAR, PCI DSS.

  • Auth0 (Okta) (US) — Identity and authentication. Processes user login data and authentication events, no customer document content. SOC 2. GDPR SCCs.

Security and compliance:

  • Snyk — Software composition analysis (dependency analysis). No access to source code or customer data. ISO 27001.

  • Scrut — Compliance platform for ISMS management (ISO 27001, SOC 2 lifecycle). No access to customer data — processes only infrastructure metadata and device compliance data. The data processed by Scrut contains no information that could identify individual insured persons or their cases. SOC 2. Transfer secured by SCCs.

Monitoring and operations:

  • BetterStack — Availability monitoring. No access to customer data.

  • Sentry — Error tracking with automatic PII scrubbing. No customer document content. SCCs.

  • Mixpanel — Product analytics (usage behavior). Receives the signed-in user's e-mail address and name, the text entered into search and filter fields, and the questions asked of the pilots — this text can contain a person's name or e-mail address. Session replay is recorded for all sessions. No customer document content and no search results are transmitted. SCCs.

  • SMS delivery service — Delivery of one-time passwords for MFA. No customer data. SCCs.

Art. 321 Swiss Criminal Code (professional secrecy): For Swiss customers whose data is subject to professional secrecy, amaise contractually ensures that confidentiality obligations are enforced throughout the entire subprocessor chain. Core processing (documents, database) remains exclusively in Switzerland. AI processing runs via Azure OpenAI Switzerland North, restricted to the Switzerland data zone; amaise logs only token counts (no prompt or completion content), and the arrangement is governed by the Microsoft Online Services DPA. Supporting US services do not process customer document content and have no access to Art. 321-protected data.

Changes to the subprocessor list are communicated to customers in advance, with the right to object under GDPR Art. 28. Transfer Impact Assessments (TIA) have been conducted and documented for all US-based subprocessors.

Did this answer your question?