Security

Enterprise-grade
security architecture

AMMOR Intelligence Group is built for organizations that handle sensitive claims data, investigative records, and government information. Security is not an add-on — it is the foundation of our architecture.

Security Framework

SOC 2 Aligned NIST Framework HIPAA Environments CJIS-Oriented Design Zero-Trust Architecture Encryption at Rest & Transit

Architecture designed around these frameworks. Not all certifications listed are independently verified at this time.

Core Security Controls

Authentication

Multi-factor authentication required for all users. Passkey and WebAuthn support. Account lockout after failed attempts. Forced password reset on first login.

Access Control

Role-based access control with 10 defined roles. Roles assigned by administrators only — users cannot select their own role. Principle of least privilege enforced.

Audit Trail

Immutable audit log on every platform action. Every claim view, score, decision, upload, and administrative action timestamped and permanently recorded.

Encryption

All data encrypted in transit using TLS. Data encrypted at rest. API communications authenticated and rate-limited.

Session Management

Configurable session timeouts. Single-session enforcement available. Secure token management with automatic refresh and revocation.

Infrastructure

Zero-trust network architecture. Isolated client environments. Regular security assessments. Vulnerability management program.

Security Inquiries

For security-related questions or to report a vulnerability: security@ammorintelligence.com