Ambria is committed to maintaining the highest standards of security, compliance, and data privacy for our customers.

SOC 2 Type II compliant (in continuous monitoring for second observation period)
Annual third-party penetration testing with independently verified security controls
Encrypts all data (TLS 1.2+ in transit, AES-256 at rest)
Does not train AI models on customer data
Deletes employee/customer data on request (within 72 business hours)
Role-based access controls (RBAC) with audit logging
CCPA-aligned with employee data rights
Sub-processors undergo security due diligence
Incident response protocols with 72-hour response commitment
Employee notification templates for CCPA compliance available
Find answers to common questions about how we protect your data and maintain compliance.