Built for public-sector security, compliance, and procurement requirements.
AMP is deployed on Microsoft Azure, authenticated through Microsoft Entra ID, and designed with the data residency, access control, audit trail, and documentation transparency requirements of public infrastructure owners.
Microsoft AzureEntra ID SSOTLS 1.3RBACFull Audit TrailUS Data ResidencyOR & WA MBE
MFA enforced through your agency's existing Entra ID policy
Conditional access policies supported — restrict access by device, location, or compliance state
Data Layer Security
Azure SQL Database with encrypted connections (TLS 1.3 required in transit)
Azure Transparent Data Encryption (TDE) at rest — AES 256-bit
Database-level access controls — no direct database access for application users
Connection strings and secrets managed through Azure Key Vault
Automated threat detection and anomaly alerting via Azure Defender
Access Control
Role-based permissions aligned to your governance structure.
Every user sees exactly what their role permits. Cross-project visibility requires explicit administrator grant.
Admin
Agency Administrator
Full platform access — user management, role assignments, configuration, audit log access, reporting, and all project data within the agency. Responsible for provisioning and deprovisioning user access.
Program
Program Manager
Full access to assigned programs and projects — all registers, documents, change orders, cost data, and reporting. Can assign project-level roles. Cannot access other program managers' programs without administrator grant.
Project
Project Team Member
Access to assigned projects only — data entry, workflow participation, document access, and status reporting within their project assignments. No cross-project visibility.
Scoped
Contractor / Consultant
Scoped access to assigned projects only. Cannot access owner-side cost data, risk registers, or program-level reporting. Document upload access only within their contractor scope. Designed for contractor coordination without owner governance exposure.
Every access grant and revocation is logged with user identity, timestamp, and authorizing administrator. The access log is part of the immutable audit trail.
Audit Trail
Every action logged. Every change traceable.
AMP's audit trail was designed from the ground up for public agency accountability requirements — not added as an afterthought.
What the audit trail captures
01
User IdentityName, email, and role for every action performed on the platform.
02
Timestamp (UTC)Precise timestamp for every record creation, modification, and deletion.
03
Before & After StateField-level change capture — what the value was, what it became, and who changed it.
04
Session & IPIP address and session identifier for every authenticated action.
05
Document Access LogWho viewed, downloaded, or modified each document — with timestamp.
06
Role ChangesWho granted what access, when, and by whose authority.
07
Workflow ApprovalsWho approved each change order, RFI response, or document review — with timestamp and role.
Legal discovery and dispute resolution documentation
Federal grant compliance documentation
The audit trail is immutable — records cannot be modified or deleted by any user, including administrators.
Data Governance
Your data. Your control. Always.
Data Residency
All program data, documents, and audit logs are stored in US-based Microsoft Azure data centers. AMP does not transfer, replicate, or process data outside the continental United States. Data residency confirmation is available in writing upon request.
Data Ownership
Your organization owns your data. AMP processes your data solely to deliver contracted services. AMP does not sell, share, license, or use client program data for any purpose outside service delivery — including model training, analytics, benchmarking, or marketing without explicit written consent.
Data Portability
You can export your program data at any time. Full export includes all project records, registers, documents, audit logs, and reporting data in standard formats (CSV, PDF, JSON). AMP provides a complete data export within 30 days of contract termination at no additional charge.
Retention & Backup
Automated daily backups. Configurable retention periods — minimum 7 years available for programs with federal funding documentation requirements. Point-in-time recovery for up to 35 days. Backup data is encrypted and stored in a geographically separate Azure region.
Encryption
Encrypted in transit. Encrypted at rest.
In Transit
TLS 1.3 enforced for all connections — older protocol versions rejected
HTTPS-only — all HTTP connections redirected to HTTPS
Certificate management through Azure-managed certificates
Perfect Forward Secrecy (PFS) enabled — session keys not reusable
At Rest
Azure SQL Transparent Data Encryption (TDE) — AES 256-bit
Azure Blob Storage server-side encryption for documents and attachments
Azure Key Vault for secrets, connection strings, and encryption key management
Key rotation managed through Azure Key Vault policies
Incident Response
Defined posture for security incidents affecting agency data.
Detection
Azure Security Center and Azure Defender provide continuous monitoring, anomaly detection, and threat intelligence for all platform components. Automated alerting for unusual access patterns, failed authentication spikes, and data exfiltration indicators.
Notification
In the event of a confirmed security incident affecting agency data, AMP commits to notifying affected agency administrators within 72 hours of confirmed incident identification — consistent with GDPR Article 33 notification timelines as a baseline standard for public-sector practice.
Containment & Recovery
Incident response procedures include immediate access suspension for compromised credentials, session revocation, forensic log preservation, and coordinated recovery with Microsoft Azure security response where infrastructure is involved.
Documentation
All security incidents are documented with timeline, scope, containment actions, root cause analysis, and remediation steps. Documentation is available to affected agencies upon request.
Accessibility
Accessibility posture for public agency requirements.
AMP is committed to accessible software for public infrastructure organizations. Current accessibility posture:
Semantic HTML structure throughout the application
Keyboard navigation support for all primary workflows
ARIA labels and roles implemented for interactive elements
Color contrast ratios targeted to WCAG 2.1 AA standards
Screen reader compatibility tested with primary assistive technologies
Accessibility Roadmap
AMP's accessibility roadmap includes formal WCAG 2.1 AA audit and remediation as part of the enterprise product maturity program. Agencies with specific accessibility requirements are encouraged to contact AMP to discuss accommodation needs.
Compliance Posture
Building toward formal certification. Aligned today.
AMP is building toward SOC 2 Type II certification. Current security controls are designed and implemented to align with SOC 2 Trust Service Criteria across Security, Availability, Processing Integrity, Confidentiality, and Privacy.
CC6–CC9
Security
Logical access controls, change management, risk assessment, and security monitoring implemented through Azure native controls and AMP application-layer RBAC.
A1
Availability
Azure App Service and SQL Database SLAs, automated failover, backup and recovery procedures, and uptime monitoring for all platform components.
PI1
Processing Integrity
Input validation, error handling, immutable audit trail, and data quality controls built into core workflows from the ground up.
C1
Confidentiality
Role-based data isolation, encryption at rest and in transit, and data classification controls preventing unauthorized access across role boundaries.
P1–P8
Privacy
Data ownership policy, access controls, data retention and destruction procedures, and incident notification procedures aligned to privacy obligations.
AMP's security documentation package for procurement review includes control descriptions, Azure architecture diagrams, and a gap assessment against SOC 2 criteria. Available to agencies on request under NDA.
Public Records & Audit Support
Designed for public agency transparency requirements.
Public Records Compliance
AMP's audit trail and document management are designed to support public records obligations. All program records stored in AMP are accessible to authorized agency administrators for export in response to public records requests. AMP does not assert any proprietary interest in agency program records.
Federal Funding Audit Support
AMP's documentation structure — cost attribution by funding source, Davis-Bacon compliance record organization, reimbursement request documentation — is designed to support IIJA, SRF, DWSRF, and ARPA reimbursement audits. Documentation workflows are specifically designed for federal audit readiness.
State & Local Audit Support
Oregon and Washington state audit requirements — including ORS 192 public records, GASB 34 capital asset documentation, and state agency audit access — are incorporated into AMP's documentation design posture.
Procurement Support
Documentation available for agency procurement review.
AMP provides a complete procurement documentation package for IT security review, legal review, and vendor evaluation processes.
Platform architecture diagram (Azure-hosted, Entra ID authentication flow, data residency)
Common questions from agency IT, legal, and procurement.
Yes. MFA is enforced through your agency's existing Microsoft Entra ID policy. AMP does not manage MFA independently — it delegates authentication entirely to your agency's Entra ID tenant, meaning your existing MFA requirements, conditional access policies, and device compliance requirements apply automatically to all AMP access. If your agency requires Compliant Device or Hybrid Azure AD Join as a condition of access, those policies are inherited by AMP sessions.
Yes. All program data, documents, and audit logs are stored in US-based Microsoft Azure data centers. AMP does not transfer, replicate, or process data outside the continental United States. AMP uses US Azure regions for primary compute, storage, and backup. Written data residency confirmation is available upon request for inclusion in agency procurement files.
No. Contractor / Consultant accounts are scoped to their assigned projects only and explicitly cannot access owner-side cost data, risk registers, program-level reporting, or any data outside their contractor scope. Document upload access is restricted to the contractor's assigned scope. Owner governance data — budget actuals, risk ratings, program-level reporting — is not visible to contractor-role accounts under any configuration.
Yes. Data portability is a fundamental commitment. You can initiate a full data export at any time during your contract. AMP provides a complete data export within 30 days of contract termination at no additional charge. Full export includes all project records, registers, change orders, RFIs, documents, audit logs, and reporting data in standard formats — CSV, PDF, and JSON. Your data does not belong to AMP.
AMP is building toward SOC 2 Type II certification. Current security controls are designed and implemented to align with SOC 2 Trust Service Criteria across Security, Availability, Processing Integrity, Confidentiality, and Privacy. AMP's security documentation package — including control descriptions, Azure architecture diagrams, and a SOC 2 gap assessment — is available to agencies on request under NDA. AMP's intention is to complete a formal SOC 2 Type II audit as part of the enterprise product maturity roadmap.
AMP relies on Microsoft Azure's built-in security infrastructure, which includes Microsoft's continuous security testing, threat intelligence programs, and vulnerability disclosure processes. AMP's application-layer security controls are reviewed as part of the SOC 2 alignment process. Independent third-party penetration testing is on AMP's security roadmap as part of the enterprise maturity program. Agencies may request the current security posture documentation for procurement review.
AMP staff access to client data is strictly controlled and limited to what is necessary for platform support and maintenance. All staff access is logged in the audit trail with user identity, timestamp, and action. AMP does not use client program data for any purpose outside contracted service delivery — including model training, analytics, benchmarking, or marketing without explicit written consent. Access to production data by AMP staff requires authorization and is auditable.
AMP's audit trail and document management are designed to support public records obligations including ORS 192 and equivalent state statutes. All program records stored in AMP are accessible to authorized agency administrators for export in response to public records requests. AMP's export tools allow administrators to produce complete record sets — including documents, change history, and communications — in response to public records requests. AMP does not assert any proprietary interest in agency program records. Records belong to the agency.
Yes. AMP's documentation structure is specifically designed for federal reimbursement audit readiness. Cost attribution by funding source, Davis-Bacon compliance record organization, reimbursement request documentation, and audit-ready project record structures support IIJA, SRF, DWSRF, and ARPA reimbursement audits. AMP's audit trail captures the documentation lineage required to demonstrate proper fund expenditure and compliance with federal program requirements.
In the event of a confirmed security incident affecting agency data, AMP commits to notifying affected agency administrators within 72 hours of confirmed incident identification — consistent with GDPR Article 33 notification timelines, which AMP uses as a baseline standard for public-sector practice even where GDPR does not technically apply. All security incidents are documented with timeline, scope, containment actions, root cause analysis, and remediation steps. Documentation is available to affected agencies upon request.
Get in Touch
Security questions before procurement? Our team works directly with agency IT, legal, and procurement staff.
We understand the documentation requirements of public agency procurement. We're ready to work with your team.