AMT Sustainability · 全面可持续数字化
Information Security

Information Security

AMT operates an ISO/IEC 27001:2022 Information Security Management System covering product R&D, platform operations and customer support, with support for customer audits, security questionnaires and tender materials.

Key facts
Certification
ISO/IEC 27001:2022 ISMS
Controls
14 control domains (ISO 27002)
Pen testing
Annual third-party
Vuln SLA
High 24h / Med 7d / Low 30d

ISO/IEC 27001 ISMS overview

AMT operates a certified ISO/IEC 27001:2022 Information Security Management System (ISMS) covering core business scope, subject to annual external surveillance audits.

  • Scope

    Product R&D, platform operations, customer support and data-centre operations are all in scope.

  • Control framework

    Implemented against ISO/IEC 27001:2022 Annex A controls with ISO 27002 guidance.

  • Continuous review

    Annual external surveillance audits by an accredited body, with recertification every three years.

14 control domains

AMT’s controls are organised along the ISO 27002 domains, spanning policy, people, technology and operations.

Security policies

Unified policy set with management review.

Organization

Defined roles, responsibilities and segregation.

People security

Screening, NDAs and security-awareness training.

Asset management

Asset inventory and data classification.

Access control

Least privilege, MFA and periodic access reviews.

Cryptography

Encryption at rest and in transit with key management.

Physical security

Data-centre access, monitoring and environmental controls.

Operations security

Change management, logging and anti-malware.

Communications

Network segmentation and secure transfer.

Secure development

Secure SDLC with code review.

Supplier relations

Sub-processor due diligence and contractual controls.

Incident management

Classification, response and post-mortem.

Business continuity

DR, RTO/RPO targets and drills.

Compliance

Legal, IP and privacy compliance.

Penetration testing & vulnerability management

  • Annual third-party pen test

    An independent firm performs black-box + grey-box testing of production each year, with incremental tests before major releases.

  • Remediation SLA

    High 24h, medium 7 days, low 30 days to close; redacted remediation notes available on request.

  • Continuous scanning

    Continuous SCA / vulnerability scanning of dependencies and images, wired into CI.

  • Disclosure channel

    Responsible disclosure accepted at security@amt.com.cn.

Customer audit support

For procurement onboarding, security reviews and tenders, AMT provides standardised audit-support materials.

  • ISO 27001 certificate copy

    Customers may request a copy of the ISO/IEC 27001 certificate and a Statement of Applicability (SoA) summary.

  • Security questionnaires

    We complete common questionnaires such as SIG / CAIQ on request.

Security FAQ

What does AMT’s ISO 27001 certification cover?

It covers product R&D, platform operations, customer support and data-centre operations. Customers can request the certificate copy to verify scope.

Can you complete a security questionnaire or share compliance materials?

Yes. We support common templates such as SIG / CAIQ and can share redacted security documentation under NDA.

Is data encrypted?

All customer data is encrypted at rest and in transit, with centrally managed keys rotated on a schedule.