Security, privacy and accountability

Understand what is implemented, what requires configuration and what remains under validation.

The Trust Center documents platform controls, data boundaries, AI use, subprocessors, continuity planning, incident readiness and the compliance roadmap without claiming certifications that have not been independently awarded.

Public trust information

Core capabilities

Designed as part of the platform—not as an isolated feature.

Security overview

Identity, access, audit, storage, payment and operational control design.

Privacy and data use

Purpose, access, retention, deletion and sensitive-data boundaries.

AI transparency

Provider use, credit accounting, raw-data limitations and human review.

Compliance roadmap

Implemented, partial, planned and externally validated control states.

How it works

A controlled workflow from setup to review.

  1. 01

    Review the relevant trust topic.

  2. 02

    Confirm which controls are implemented and configured.

  3. 03

    Identify customer or institution responsibilities.

  4. 04

    Request detailed evidence under an appropriate agreement.

  5. 05

    Complete independent validation before relying on a certification claim.

Frequently asked questions

Clear answers before activation.

Is Amexwrite SOC 2 certified?

The platform includes a compliance evidence system, but no external certification should be claimed until an independent auditor has completed and issued the applicable report.

Is Amexwrite HIPAA compliant?

Compliance depends on the complete deployed environment, contracts, policies, configuration, training and risk managementu2014not software features alone.

Next step

Need a security or data review?

Contact Amexwrite with the scope and organization requirements.

Contact trust team