Security & Trust  ·  CIO & Procurement Reference

Built for public-sector security, compliance,
and procurement requirements.

AMP is deployed on Microsoft Azure, authenticated through Microsoft Entra ID, and designed with the data residency, access control, audit trail, and documentation transparency requirements of public infrastructure owners.

Microsoft Azure Entra ID SSO TLS 1.3 RBAC Full Audit Trail US Data Residency OR & WA MBE
Platform Architecture

Hosted on infrastructure public agencies already trust.

Azure Cloud Hosting
Azure App Service — managed, auto-scaling, 99.9% uptime SLA
Azure SQL Database — managed relational database with built-in high availability
US-based Azure regions — all data stored within the continental United States
Azure-managed infrastructure security, patching, network isolation, and DDoS protection
No on-premises infrastructure required — fully cloud-native
Microsoft Entra ID Authentication
Microsoft Entra ID (Azure Active Directory) SSO
Your agency's existing M365 credentials — no new passwords
SAML 2.0 / OAuth 2.0 / OpenID Connect — industry-standard protocols
MFA enforced through your agency's existing Entra ID policy
Conditional access policies supported — restrict access by device, location, or compliance state
Data Layer Security
Azure SQL Database with encrypted connections (TLS 1.3 required in transit)
Azure Transparent Data Encryption (TDE) at rest — AES 256-bit
Database-level access controls — no direct database access for application users
Connection strings and secrets managed through Azure Key Vault
Automated threat detection and anomaly alerting via Azure Defender
Access Control

Role-based permissions aligned to your governance structure.

Every user sees exactly what their role permits. Cross-project visibility requires explicit administrator grant.

Admin
Agency Administrator
Full platform access — user management, role assignments, configuration, audit log access, reporting, and all project data within the agency. Responsible for provisioning and deprovisioning user access.
Program
Program Manager
Full access to assigned programs and projects — all registers, documents, change orders, cost data, and reporting. Can assign project-level roles. Cannot access other program managers' programs without administrator grant.
Project
Project Team Member
Access to assigned projects only — data entry, workflow participation, document access, and status reporting within their project assignments. No cross-project visibility.
Scoped
Contractor / Consultant
Scoped access to assigned projects only. Cannot access owner-side cost data, risk registers, or program-level reporting. Document upload access only within their contractor scope. Designed for contractor coordination without owner governance exposure.
Every access grant and revocation is logged with user identity, timestamp, and authorizing administrator. The access log is part of the immutable audit trail.
Audit Trail

Every action logged. Every change traceable.

AMP's audit trail was designed from the ground up for public agency accountability requirements — not added as an afterthought.

What the audit trail captures
01
User IdentityName, email, and role for every action performed on the platform.
02
Timestamp (UTC)Precise timestamp for every record creation, modification, and deletion.
03
Before & After StateField-level change capture — what the value was, what it became, and who changed it.
04
Session & IPIP address and session identifier for every authenticated action.
05
Document Access LogWho viewed, downloaded, or modified each document — with timestamp.
06
Role ChangesWho granted what access, when, and by whose authority.
07
Workflow ApprovalsWho approved each change order, RFI response, or document review — with timestamp and role.
08
Failed AuthenticationAll failed login attempts — user, IP, timestamp, failure reason.
What the audit trail is designed to support
Federal reimbursement audits (IIJA, SRF, DWSRF)
State and local agency financial audits
Public records requests (ORS 192 and equivalent)
Internal governance and oversight reviews
Legal discovery and dispute resolution documentation
Federal grant compliance documentation
The audit trail is immutable — records cannot be modified or deleted by any user, including administrators.
Data Governance

Your data. Your control. Always.

Data Residency
All program data, documents, and audit logs are stored in US-based Microsoft Azure data centers. AMP does not transfer, replicate, or process data outside the continental United States. Data residency confirmation is available in writing upon request.
Data Ownership
Your organization owns your data. AMP processes your data solely to deliver contracted services. AMP does not sell, share, license, or use client program data for any purpose outside service delivery — including model training, analytics, benchmarking, or marketing without explicit written consent.
Data Portability
You can export your program data at any time. Full export includes all project records, registers, documents, audit logs, and reporting data in standard formats (CSV, PDF, JSON). AMP provides a complete data export within 30 days of contract termination at no additional charge.
Retention & Backup
Automated daily backups. Configurable retention periods — minimum 7 years available for programs with federal funding documentation requirements. Point-in-time recovery for up to 35 days. Backup data is encrypted and stored in a geographically separate Azure region.
Encryption

Encrypted in transit. Encrypted at rest.

In Transit
TLS 1.3 enforced for all connections — older protocol versions rejected
HTTPS-only — all HTTP connections redirected to HTTPS
Certificate management through Azure-managed certificates
Perfect Forward Secrecy (PFS) enabled — session keys not reusable
At Rest
Azure SQL Transparent Data Encryption (TDE) — AES 256-bit
Azure Blob Storage server-side encryption for documents and attachments
Azure Key Vault for secrets, connection strings, and encryption key management
Key rotation managed through Azure Key Vault policies
Incident Response

Defined posture for security incidents affecting agency data.

Detection
Azure Security Center and Azure Defender provide continuous monitoring, anomaly detection, and threat intelligence for all platform components. Automated alerting for unusual access patterns, failed authentication spikes, and data exfiltration indicators.
Notification
In the event of a confirmed security incident affecting agency data, AMP commits to notifying affected agency administrators within 72 hours of confirmed incident identification — consistent with GDPR Article 33 notification timelines as a baseline standard for public-sector practice.
Containment & Recovery
Incident response procedures include immediate access suspension for compromised credentials, session revocation, forensic log preservation, and coordinated recovery with Microsoft Azure security response where infrastructure is involved.
Documentation
All security incidents are documented with timeline, scope, containment actions, root cause analysis, and remediation steps. Documentation is available to affected agencies upon request.
Accessibility

Accessibility posture for public agency requirements.

AMP is committed to accessible software for public infrastructure organizations. Current accessibility posture:

Semantic HTML structure throughout the application
Keyboard navigation support for all primary workflows
ARIA labels and roles implemented for interactive elements
Color contrast ratios targeted to WCAG 2.1 AA standards
Screen reader compatibility tested with primary assistive technologies
Accessibility Roadmap AMP's accessibility roadmap includes formal WCAG 2.1 AA audit and remediation as part of the enterprise product maturity program. Agencies with specific accessibility requirements are encouraged to contact AMP to discuss accommodation needs.
Compliance Posture

Building toward formal certification. Aligned today.

AMP is building toward SOC 2 Type II certification. Current security controls are designed and implemented to align with SOC 2 Trust Service Criteria across Security, Availability, Processing Integrity, Confidentiality, and Privacy.

CC6–CC9
Security
Logical access controls, change management, risk assessment, and security monitoring implemented through Azure native controls and AMP application-layer RBAC.
A1
Availability
Azure App Service and SQL Database SLAs, automated failover, backup and recovery procedures, and uptime monitoring for all platform components.
PI1
Processing Integrity
Input validation, error handling, immutable audit trail, and data quality controls built into core workflows from the ground up.
C1
Confidentiality
Role-based data isolation, encryption at rest and in transit, and data classification controls preventing unauthorized access across role boundaries.
P1–P8
Privacy
Data ownership policy, access controls, data retention and destruction procedures, and incident notification procedures aligned to privacy obligations.
AMP's security documentation package for procurement review includes control descriptions, Azure architecture diagrams, and a gap assessment against SOC 2 criteria. Available to agencies on request under NDA.
Public Records & Audit Support

Designed for public agency transparency requirements.

Public Records Compliance
AMP's audit trail and document management are designed to support public records obligations. All program records stored in AMP are accessible to authorized agency administrators for export in response to public records requests. AMP does not assert any proprietary interest in agency program records.
Federal Funding Audit Support
AMP's documentation structure — cost attribution by funding source, Davis-Bacon compliance record organization, reimbursement request documentation — is designed to support IIJA, SRF, DWSRF, and ARPA reimbursement audits. Documentation workflows are specifically designed for federal audit readiness.
State & Local Audit Support
Oregon and Washington state audit requirements — including ORS 192 public records, GASB 34 capital asset documentation, and state agency audit access — are incorporated into AMP's documentation design posture.
Procurement Support

Documentation available for agency procurement review.

AMP provides a complete procurement documentation package for IT security review, legal review, and vendor evaluation processes.

Platform architecture diagram (Azure-hosted, Entra ID authentication flow, data residency)
Data residency and sovereignty statement
Access control specification document
Audit trail capability description
Encryption specification (in transit and at rest)
Backup and retention policy summary
Incident notification procedure
SOC 2 alignment gap assessment
Implementation scope templates for RFP attachment
MBE certification documentation (OR MBE & ESB #10297, WA MBE M5M0028131)
All procurement documentation is provided under NDA upon request. Typical turnaround: 3–5 business days.
Security FAQ

Common questions from agency IT, legal, and procurement.

Yes. MFA is enforced through your agency's existing Microsoft Entra ID policy. AMP does not manage MFA independently — it delegates authentication entirely to your agency's Entra ID tenant, meaning your existing MFA requirements, conditional access policies, and device compliance requirements apply automatically to all AMP access. If your agency requires Compliant Device or Hybrid Azure AD Join as a condition of access, those policies are inherited by AMP sessions.
Yes. All program data, documents, and audit logs are stored in US-based Microsoft Azure data centers. AMP does not transfer, replicate, or process data outside the continental United States. AMP uses US Azure regions for primary compute, storage, and backup. Written data residency confirmation is available upon request for inclusion in agency procurement files.
No. Contractor / Consultant accounts are scoped to their assigned projects only and explicitly cannot access owner-side cost data, risk registers, program-level reporting, or any data outside their contractor scope. Document upload access is restricted to the contractor's assigned scope. Owner governance data — budget actuals, risk ratings, program-level reporting — is not visible to contractor-role accounts under any configuration.
Yes. Data portability is a fundamental commitment. You can initiate a full data export at any time during your contract. AMP provides a complete data export within 30 days of contract termination at no additional charge. Full export includes all project records, registers, change orders, RFIs, documents, audit logs, and reporting data in standard formats — CSV, PDF, and JSON. Your data does not belong to AMP.
AMP is building toward SOC 2 Type II certification. Current security controls are designed and implemented to align with SOC 2 Trust Service Criteria across Security, Availability, Processing Integrity, Confidentiality, and Privacy. AMP's security documentation package — including control descriptions, Azure architecture diagrams, and a SOC 2 gap assessment — is available to agencies on request under NDA. AMP's intention is to complete a formal SOC 2 Type II audit as part of the enterprise product maturity roadmap.
AMP relies on Microsoft Azure's built-in security infrastructure, which includes Microsoft's continuous security testing, threat intelligence programs, and vulnerability disclosure processes. AMP's application-layer security controls are reviewed as part of the SOC 2 alignment process. Independent third-party penetration testing is on AMP's security roadmap as part of the enterprise maturity program. Agencies may request the current security posture documentation for procurement review.
AMP staff access to client data is strictly controlled and limited to what is necessary for platform support and maintenance. All staff access is logged in the audit trail with user identity, timestamp, and action. AMP does not use client program data for any purpose outside contracted service delivery — including model training, analytics, benchmarking, or marketing without explicit written consent. Access to production data by AMP staff requires authorization and is auditable.
AMP's audit trail and document management are designed to support public records obligations including ORS 192 and equivalent state statutes. All program records stored in AMP are accessible to authorized agency administrators for export in response to public records requests. AMP's export tools allow administrators to produce complete record sets — including documents, change history, and communications — in response to public records requests. AMP does not assert any proprietary interest in agency program records. Records belong to the agency.
Yes. AMP's documentation structure is specifically designed for federal reimbursement audit readiness. Cost attribution by funding source, Davis-Bacon compliance record organization, reimbursement request documentation, and audit-ready project record structures support IIJA, SRF, DWSRF, and ARPA reimbursement audits. AMP's audit trail captures the documentation lineage required to demonstrate proper fund expenditure and compliance with federal program requirements.
In the event of a confirmed security incident affecting agency data, AMP commits to notifying affected agency administrators within 72 hours of confirmed incident identification — consistent with GDPR Article 33 notification timelines, which AMP uses as a baseline standard for public-sector practice even where GDPR does not technically apply. All security incidents are documented with timeline, scope, containment actions, root cause analysis, and remediation steps. Documentation is available to affected agencies upon request.
Get in Touch

Security questions before procurement? Our team works directly with agency IT, legal, and procurement staff.

We understand the documentation requirements of public agency procurement. We're ready to work with your team.

Transparency Commitments

What AMP Does Not Do

Enterprise buyers deserve to know the boundaries of the platform they are evaluating. These commitments are unconditional.

Agency data is never sold
AMP does not sell, license, or share agency data with third parties under any circumstances.
Agency data does not train public AI models
Client data is never used to train publicly available AI or machine learning models.
No replacement of existing M365 investments
AMP is designed to extend your Microsoft 365 environment, not replace or conflict with it.
No production exposure during evaluation
Evaluations and pilots use isolated environments. Your production systems are never required during the evaluation phase.
No client references published without approval
AMP does not publish, reference, or name client deployments without explicit written authorization.
No hidden data flows to third-party analytics
All data flows are documented and disclosed. No undisclosed analytics, advertising, or tracking integrations.
Architecture

High-Level Deployment Architecture

AMP is deployed on Microsoft Azure, authenticated via Entra ID, and structured for public-sector security, audit, and data residency requirements.

Agency Staff
PM Teams
Executives
Field Crews
Microsoft Entra ID SSO & RBAC
AMP PMIS Essentials
SharePoint / Cloud
AMP Insight
Intelligence Layer
Microsoft Azure — US Data Residency
App Service
Azure SQL
Blob Storage
Key Vault
TLS 1.3 Encryption
Full Audit Log
Optional Integrations
GIS / ArcGIS
CMMS
ERP / Finance
Power BI
SharePoint Online
IoT / SCADA

High-level reference architecture. Detailed implementation diagrams available under NDA for qualified procurement engagements.