Security & compliance
Regulated research needs controls that are always on.
AMDana was written for organizations that handle protected health information, sponsor data and unpublished findings. These controls are identical on every tier.
HIPAA-compliance ready
Administrative, technical and physical safeguards mapped to the Security Rule: access control, audit controls, integrity, transmission security, and PHI-safe notifications. A Business Associate Agreement is available for covered entities and their business associates.
Included on every tierTwo-factor authentication
Authenticator-app TOTP is the second factor. Enforced by default for every account, including external collaborators, who must enroll before their seat activates.
Included on every tierAutomatic log-off
Idle sessions end on their own (default 20 minutes, configurable), with rolling refresh for active users. Passwords rotate on a 90-day policy.
Included on every tierAudit-ready trail
Sign-in and sign-out, denied access, session expiry, invitations, policy acknowledgements, grant activation, deletions and restores — exportable for funders, sponsors and auditors.
Included on every tierTenant isolation
Every organization is its own tenant. A request for another tenant's record answers 404 — it does not exist from where you stand.
Included on every tierBackups and durability
SQLite WAL with nightly encrypted offsite backups and restore drills. Files are content-addressed with SHA-256 and written atomically.
Included on every tierPHI-safe off-app alerts
Email, SMS and push notifications carry sender, priority and a sign-in link. Message bodies, titles and filenames never leave the application.
Included on every tierTransport and headers
TLS everywhere, HSTS, a strict Content Security Policy with no inline script, nosniff, referrer and permissions policies.
Included on every tierIdentity and sessions
Passwords are hashed with bcrypt and rotate every 90 days. The second factor is an authenticator app (TOTP); enforcement is on by default and covers external collaborators before their seat activates. Sessions end after a configurable idle period with rolling refresh for active users, and sign-out withdraws push subscriptions from the device.
Data isolation
Each customer organization is a tenant with its own federation record. Every query is scoped to the caller's tenant and cross-tenant requests answer 404. Platform administration is a separate role that is never granted to customer accounts.
Audit
AMDana records sign-in and sign-out, denied access, session expiry, invitation lifecycle, policy acknowledgements, grant activation and activity, deletions and restores. Exports are available to administrators for funders, sponsors, IRBs and auditors.
Files and backups
Uploads are written atomically to persistent storage, content-addressed with SHA-256, size-capped and MIME-allowlisted. The database runs in WAL mode with nightly encrypted offsite backups and periodic restore verification.
Notifications
Off-application email, SMS and push notifications carry the sender, the priority and a sign-in link — never a message body, title or filename. Web push uses RFC 8291 encryption and RFC 8292 VAPID identity.
Transport and browser security
TLS for every connection, HTTP Strict Transport Security, a strict Content Security Policy that forbids inline script, X-Content-Type-Options nosniff, Referrer-Policy and Permissions-Policy headers. The camera is available only to the application itself for AMDana Connect photo capture.
Responsible disclosure
Report a suspected vulnerability to support@amdana.app. We acknowledge within two business days.
Ready when you are
License AMDana today. Your tenant is live minutes after checkout.
Choose a tier, complete secure payment with Stripe, and your administrator receives a welcome email with a temporary password. No sales call required — unless you want one.