Security & Isolation

Every family's data is a private estate — never a shared lot.

Family offices don't just ask whether data is encrypted. They ask who else could possibly see it. Amara is designed so that the honest answer is always: no one who isn't supposed to — checked more than once, and in more than one way.

The Model

Isolation is layered, not assumed.

No single control is asked to carry the whole promise. Each client is separated from every other client at the environment level, each person is separated from data outside their mandate at the role level, and every action is separated from anonymity by a permanent record.

01Client Isolation

A dedicated environment for every family office.

Each client's data is held in its own logically separate environment — not a shared index or a shared database filtered by a flag. One family office's records are never queried, searched, or retrieved through the same path as another's.

02Role Isolation

Access follows the mandate, not the login.

Within a single office, principals, family members, controllers and advisors each see only what their role permits. A staff member preparing a report and a principal reviewing their own holdings are shown two different views of the truth, by design — not by convention.

03Governance Isolation

Every action is attributable, permanently.

Who asked, what was answered, who approved, and when — recorded as a matter of course, not reconstructed after the fact. If a question is ever raised about how a decision was reached, the office already holds the answer.

In Practice

What this means, day to day.

Encryption

In transit and at rest

Data is encrypted continuously, whether it's moving between systems or sitting in storage — with no unencrypted intermediate step.

Human Review

For anything sensitive

Changes that matter — new rules, new access, new entities — pass through a person before they take effect. Amara accelerates the routine; it doesn't remove judgment from the exceptional.

Least Privilege

By default, not by request

New users start with the minimum access their role requires. Broader access is a deliberate decision, not a default setting someone forgot to change.

Standards We Build Toward

Held to the bar institutional partners expect.

SOC 2 Type II ISO 27001 GDPR HIPAA-Aligned Handling Least-Privilege Access Full Audit Trail
Questions Welcome

Ask us anything your due-diligence checklist requires.

We're glad to go deeper on isolation architecture, access control, and data handling in a direct conversation with your team.