Amboras · Trust Center

Amboras Trust Center

Trust center

Amboras maintains a public trust center documenting SOC 2 Type II, ISO 27001, PCI DSS, HIPAA Ready, GDPR, and CCPA compliance.

CompanyE-CommerceAIGenerative AIAutomationConversion Rate OptimizationRetailNo-Code Store BuilderY CombinatorAgentic CommerceStorefrontPaymentsCheckoutAnalyticsHeadless CommerceMedusaPluginsMulti-Tenant
Trust center: https://www.amboras.com/security

Certifications & Compliance

SOC 2 Type IIISO 27001PCI DSSHIPAA ReadyGDPRCCPA

Source

Trust Center

amboras-trust-center.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.amboras.com/security
url: https://www.amboras.com/security
self_reported: true
independently_verified: false
trust_portal: none
note: >-
  Certifications are self-published by Amboras on its public /security page under a
  "Compliance and certifications" section; not independently verified. Wording captured
  verbatim - note "HIPAA Ready" (readiness, not certification) and "SOC 2 Type II"
  specifically, not plain SOC 2. Amboras runs no trust portal: there is no trust.amboras.com,
  no audit report, no certificate number and no auditor named anywhere on the public site, so
  there is nothing to verify these claims against. Re-confirmed on the live page 2026-08-13.
certifications:
- SOC 2 Type II
- ISO 27001
- PCI DSS
- HIPAA Ready
- GDPR
- CCPA
as_published:
- name: SOC 2 Type II
  caption: Audited security controls
- name: GDPR
  caption: EU data protection
- name: ISO 27001
  caption: Information security management
- name: CCPA
  caption: California privacy compliance
- name: PCI DSS
  caption: Payment card security
- name: HIPAA Ready
  caption: Healthcare data readiness
  caveat: Readiness, not certification. Captured verbatim.
enterprise_only:
  entitlements:
  - SOC 2
  - SCIM
  - audit log
  - sandbox
  source: https://www.amboras.com/pricing
  note: >-
    The Enterprise tier lists SOC 2, SCIM, audit log and sandbox as tier entitlements, which
    sits oddly beside the /security page presenting SOC 2 Type II as a platform-wide
    certification. Both are recorded as published.
incident_response:
  breach_notification: within 72 hours
  source: https://www.amboras.com/security
subprocessors:
- name: Supabase
  role: Authentication and database
- name: Stripe
  role: Payment processing, PCI DSS Level 1
- name: Fly.io
  role: Infrastructure hosting
- name: AWS
  role: Backup and storage
evidence:
- source: https://www.amboras.com/security
  section: Compliance and certifications
  http_status: 200
  keywords:
  - soc 2 type ii
  - iso 27001
  - pci dss
  - hipaa
  - gdpr
  - ccpa