Security
Amrachi is designed for professional organisations requiring accountable and traceable portfolio-supervision workflows. This page is a high-level security overview, not a certification statement.
Last updated: 4 September 2026
1. Infrastructure and hosting
Amrachi uses managed cloud infrastructure. The primary Supabase production database is hosted in Zurich, Switzerland. Other providers may process limited technical or service data in other jurisdictions as described in the Privacy Policy and Subprocessor List.
2. Access control and customer separation
Access to Customer Data is restricted through authentication, authorisation and organisation-scoping controls appropriate to the relevant role and function. Amrachi applies technical controls designed to restrict customer users to authorised organisations, data and functions, including database-level row-security controls where applicable.
3. Authentication and abuse prevention
Authentication is provided through managed authentication infrastructure. Security-sensitive authentication flows may use Cloudflare Turnstile to reduce automated abuse. Customers remain responsible for maintaining appropriate user access within their organisation.
4. Encryption
Amrachi uses encrypted network connections for transmission of Service data. Managed infrastructure used by the primary application provides encryption at rest for stored application data. Provider-specific algorithms and protocol details are maintained in due-diligence materials rather than presented as a universal guarantee.
5. Logging, monitoring and diagnostics
Amrachi uses operational and security logging for reliability, troubleshooting and incident response. Sentry is used for application error and performance monitoring. Amrachi configures Sentry to minimise diagnostic data, including disabling Session Replay and default PII transmission and applying event-sanitisation controls. The Sentry organisation uses an EU data-storage region.
6. Secure development and change control
Application changes are version controlled and subject to automated testing and deployment controls. Security-sensitive controls are designed to fail closed where appropriate.
7. Evidence integrity
Amrachi applies cryptographic integrity mechanisms designed to make subsequent alteration of recorded supervision evidence detectable. “Tamper-evident” does not mean immutable or tamper-proof. Integrity verification concerns integrity and consistency of the evidence record and does not determine whether an underlying investment or supervision decision was correct or compliant.
8. Incident management
Amrachi maintains processes designed to identify, assess, contain and respond to security-relevant events. Where a personal-data breach affects Customer Personal Data processed on behalf of a customer, Amrachi will notify that customer without undue delay after becoming aware, in accordance with the DPA and applicable law.
9. Resilience and backups
Amrachi relies on managed infrastructure and operational procedures designed to support service resilience and recovery. Specific backup periods, RTOs or RPOs are not publicly promised unless expressly verified and contractually agreed.
10. Vendor management and contact
Amrachi assesses service providers according to the nature of the service and data involved. Providers processing Customer Personal Data on behalf of Amrachi are identified in the Subprocessor List. Security concerns may be reported to security@amrachi.ch. Qualified customers and prospects may request additional due-diligence information.