Third Party Index

Snapshot 33931

Document
Trust center
URL
https://www.amplemarket.com/legal/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
140472 bytes
SHA-256 (raw)
c5f1417056d5be97ea302032b72594eadda55809fe095968517b20ccec175877
SHA-256 (normalized text)
2e0b6f40079253aa3c2c3677554fd1e257984e3fe454f5b431fab06e2daf0208

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security at Amplemarket
SOC 2 Compliance & Security Assurance
At Amplemarket, trust and transparency are foundational to everything we do. We are proud to maintain a SOC 2 Type II certification, demonstrating our commitment to the highest standards of security, availability, and confidentiality. For more details about our security posture and compliance documentation, please visit our Trust Portal.
Data Security
Amplemarket encrypts data at rest and in transit for all of our customers. We use tools like Google Cloud Platform’s Cloud Key Management solution to manage encryption keys using hardware security modules for maximum security in line with industry best practices.
Application Security
Amplemarket regularly engages some of the industry’s best application security experts for third-party penetration tests. Our penetration testers evaluate the source code, running application, and the deployed environment. Additionally, we make available a vulnerability disclosure form that will allow any security researchers to make us aware of potential security related issues in our product and systems.
Amplemarket also uses high-quality static analysis tooling provided by GitHub Advanced Security such as Secrets Scanner, and Dependabot, as well as SonarQube’s code quality and vulnerability scanning to secure our product at every step of the development process.
Infrastructure Security
Amplemarket uses Google Cloud to host our application. We make full use of the security products embedded within the GCP ecosystem, including CKM, Secrets Manager, Cloud Audit Logs, Identity-aware Proxy, and Event Threat Detection.
In addition, we deploy our application using containers that run on GCP managed services, meaning we typically do not manage servers or Compute instances in production.