Security, privacy & compliance built for modern care.

Learn how Amigo Assist protects data with privacy-first design, encrypted data flows, controlled access, audit-ready operations and UK/EU hosting — giving providers, local authorities and procurement teams a clearer, more practical foundation for secure monitoring.

1

Security controls

Encryption in transit and at rest, role-based access, least-privilege permissions and centralised audit logging.

2

Privacy & hosting

Privacy-first design, UK/EU hosting options, controlled data access and clear retention and deletion principles.

3

Assurance roadmap

Documentation and assurance support for reviews, with roadmap visibility across Cyber Essentials, NHS DSPT and ISO 27001.

Covers security controls, privacy and data protection, hosting, assurance support and compliance roadmap information.

Security controls, privacy-first design and assurance-ready operations

Amigo Assist is designed to support security reviews, privacy and data protection expectations, procurement conversations and operational assurance. Our approach combines encrypted data flows, controlled access, audit-ready logging, UK/EU hosting and clear governance principles.

Encryption & key management

  • Encrypted data in transit using modern HTTPS/TLS standards
  • Encryption at rest with managed key controls
  • Secrets handled securely rather than stored in code
  • Key administration kept restricted and auditable

Access control & identity

  • Role-based access across the platform
  • Least-privilege permissions for operational access
  • Additional protection for privileged operations
  • Controlled sharing, user invitation management and permission boundaries

Logging, monitoring & audit

  • Centralised application and infrastructure logging
  • Audit trails for access and configuration changes
  • Monitoring and alerting for security-relevant events
  • Evidence-friendly operations for supplier assurance and procurement reviews

This page also covers privacy, hosting and compliance assurance

Beyond core security controls, the sections below explain Amigo Assist’s privacy and data protection approach, UK/EU hosting position, retention and deletion principles, incident readiness and roadmap visibility for broader assurance conversations.

Privacy & data protection by design

Amigo Assist is built with a privacy-first approach to support dignity, appropriate access, controlled data handling and clear governance. We aim to minimise unnecessary exposure, restrict access to authorised users and support customers with wider data protection responsibilities.

Privacy-first approach

  • Designed to support dignity, proportionality and appropriate use in care environments
  • Privacy considerations are built into platform design, operational processes and customer onboarding
  • We aim to limit unnecessary exposure of personal information through controlled workflows and permissions
  • Full privacy notice and legal detail are available on our Privacy page

Data handling & access

  • Access to data is restricted through role-based permissions and least-privilege operational controls
  • User access, invitations and sharing are managed in a controlled manner with defined permission boundaries
  • Operational access is limited to authorised personnel and supported by audit-friendly controls
  • Customers can discuss information governance, DPIA support and assurance requirements with our team

Retention, deletion & rights

  • We aim to apply clear retention and deletion principles across customer data, operational records and backups
  • Offboarding and contract-end processes can include controlled deletion or return arrangements where applicable
  • We work with customers to support appropriate handling of data subject rights and governance queries
  • Additional governance documentation is available through our procurement and assurance materials

Need the full legal and assurance detail?

This section provides a high-level overview of Amigo Assist’s privacy and data protection approach. For full legal information, please view our Privacy page. For procurement, governance and due diligence requests, you can also request our Procurement Pack.

Data hosting, retention & deletion

Amigo Assist is designed to support clear data residency, controlled lifecycle management and structured offboarding. We aim to give customers confidence in where data is hosted, how it is governed through its lifecycle and how deletion or return arrangements can be handled where applicable.

UK/EU data hosting

  • UK/EU hosting options can support customer and procurement requirements
  • Hosting environments are selected to support security, resilience and governance expectations
  • Data residency expectations can be discussed as part of assurance and review processes
  • Further hosting detail can be shared through procurement materials where appropriate

Retention & lifecycle management

  • Defined retention principles are applied across customer data, logs, records and backups
  • Retention periods are intended to balance operational needs, resilience and governance obligations
  • Lifecycle handling is considered from onboarding through live use, support, archival and offboarding
  • More detailed retention information can be discussed during assurance, procurement or contract review

Deletion & offboarding

  • Customer offboarding can include structured deletion or return arrangements where relevant to the service model
  • Deprovisioning and access removal are handled in a controlled manner to reduce lingering access
  • Backup and recovery processes are considered as part of the wider deletion and lifecycle approach
  • Customers can raise data lifecycle and offboarding questions as part of procurement and governance review

Clear hosting and lifecycle information supports better assurance reviews

This section provides a high-level overview of hosting, retention and deletion principles. For deeper infrastructure, governance and due diligence information, customers can request our Procurement Pack or contact the team directly.

Incident response & assurance support

Amigo Assist is designed to support timely incident handling, controlled escalation and practical assurance conversations. We aim to combine monitoring, response readiness and evidence-friendly governance support for customers, providers and procurement teams.

Detection & triage

  • Monitoring and alerting help support early visibility of security-relevant events
  • Events can be assessed and triaged according to severity, potential impact and urgency
  • Centralised logging and audit trails help support investigation and technical review
  • Operational processes are intended to support structured incident assessment rather than ad hoc handling

Response, escalation & remediation

  • Internal escalation can involve the right technical and operational stakeholders where needed
  • Containment, investigation and remediation actions are intended to be tracked through a controlled process
  • Where appropriate, customer communication can form part of the wider incident handling and governance process
  • Lessons learned and follow-up improvements can inform stronger controls over time

Assurance, DPIAs & procurement support

  • Customers can request assurance information to support procurement, supplier review and governance processes
  • We can support conversations around DPIAs, information governance expectations and security questionnaires
  • Our controls and documentation are intended to support evidence-based assurance conversations, not just headline claims
  • Further detail can be shared through direct engagement and our Procurement Pack where appropriate

Practical assurance support matters as much as technical controls

This section outlines our approach to incident handling and assurance support at a high level. For procurement, governance, questionnaire and due diligence requests, customers can contact the team or request the Procurement Pack.

Compliance roadmap

We are building our assurance posture in a structured and transparent way. These roadmap items reflect how Amigo Assist is strengthening governance, security and assurance as we grow across family, provider and public sector settings.

Roadmap

Cyber Essentials

Cyber Essentials supports baseline cyber hygiene and control maturity, helping strengthen assurance conversations with providers, partners and commissioners.

Status: Planned
Roadmap

NHS DSPT

NHS DSPT alignment supports health and care-sector assurance expectations, especially where governance, supplier due diligence and information handling standards matter.

Status: Roadmap priority
Long-term roadmap

ISO 27001

ISO 27001 represents a longer-term maturity pathway for formal information security governance, risk management and continuous improvement as the platform scales.

Status: Planned progression

Roadmap items are shared transparently and may evolve with customer, procurement and regulatory requirements. For current assurance discussions, governance reviews and due diligence requests, ask for our Procurement Pack.

Platform architecture & technical controls

A technical summary of how Amigo Assist applies layered controls across infrastructure, data handling, access, logging and resilience to support secure service delivery, governance conversations and assurance reviews.

Infrastructure security

  • Network segmentation: private services and restricted ingress designed around the principle of least exposure.
  • Edge protection: rate limiting and request filtering to help reduce abuse, automated scanning and unwanted traffic.
  • Secrets management: no secrets in code, with controlled secret storage and rotation practices.
  • Patch & dependency hygiene: routine updates and monitored vulnerabilities across infrastructure and third-party packages.

Data, logging & resilience

  • Encryption: TLS in transit and encryption at rest using managed keys.
  • Identity & access: role-based access controls, additional protection for privileged roles and periodic access review processes.
  • Auditability: centralised logs and traceability for key administrative and configuration actions.
  • Backups & recovery: routine backups and recovery procedures aligned to service resilience requirements.

Need deeper technical detail on data flows, sub-processors, incident handling, retention schedules or DPIA support?

Request Procurement Pack

Frequently asked questions

Yes. Amigo Assist supports UK/EU hosting options to align with customer, procurement and governance requirements. Environment-specific hosting, data residency and related infrastructure details can be discussed as part of security and assurance review.