Information Security
AMT operates an ISO/IEC 27001:2022 Information Security Management System covering product R&D, platform operations and customer support, with support for customer audits, security questionnaires and tender materials.
- Certification
- ISO/IEC 27001:2022 ISMS
- Controls
- 14 control domains (ISO 27002)
- Pen testing
- Annual third-party
- Vuln SLA
- High 24h / Med 7d / Low 30d
ISO/IEC 27001 ISMS overview
AMT operates a certified ISO/IEC 27001:2022 Information Security Management System (ISMS) covering core business scope, subject to annual external surveillance audits.
- Scope
Product R&D, platform operations, customer support and data-centre operations are all in scope.
- Control framework
Implemented against ISO/IEC 27001:2022 Annex A controls with ISO 27002 guidance.
- Continuous review
Annual external surveillance audits by an accredited body, with recertification every three years.
14 control domains
AMT’s controls are organised along the ISO 27002 domains, spanning policy, people, technology and operations.
Security policies
Unified policy set with management review.
Organization
Defined roles, responsibilities and segregation.
People security
Screening, NDAs and security-awareness training.
Asset management
Asset inventory and data classification.
Access control
Least privilege, MFA and periodic access reviews.
Cryptography
Encryption at rest and in transit with key management.
Physical security
Data-centre access, monitoring and environmental controls.
Operations security
Change management, logging and anti-malware.
Communications
Network segmentation and secure transfer.
Secure development
Secure SDLC with code review.
Supplier relations
Sub-processor due diligence and contractual controls.
Incident management
Classification, response and post-mortem.
Business continuity
DR, RTO/RPO targets and drills.
Compliance
Legal, IP and privacy compliance.
Penetration testing & vulnerability management
- Annual third-party pen test
An independent firm performs black-box + grey-box testing of production each year, with incremental tests before major releases.
- Remediation SLA
High 24h, medium 7 days, low 30 days to close; redacted remediation notes available on request.
- Continuous scanning
Continuous SCA / vulnerability scanning of dependencies and images, wired into CI.
- Disclosure channel
Responsible disclosure accepted at security@amt.com.cn.
Customer audit support
For procurement onboarding, security reviews and tenders, AMT provides standardised audit-support materials.
- ISO 27001 certificate copy
Customers may request a copy of the ISO/IEC 27001 certificate and a Statement of Applicability (SoA) summary.
- Security questionnaires
We complete common questionnaires such as SIG / CAIQ on request.
Security FAQ
What does AMT’s ISO 27001 certification cover?
It covers product R&D, platform operations, customer support and data-centre operations. Customers can request the certificate copy to verify scope.
Can you complete a security questionnaire or share compliance materials?
Yes. We support common templates such as SIG / CAIQ and can share redacted security documentation under NDA.
Is data encrypted?
All customer data is encrypted at rest and in transit, with centrally managed keys rotated on a schedule.

