AMBILL: SECURITY & SOC 1 TYPE II COMPLIANCE

Enterprise-Grade Security & Compliance for Financial Operations

Ambill is verified SOC 1 Type II compliant under AICPA SSAE 18 standards. We protect your accounts receivable, accounts payable, and financial reconciliation with cryptographic disk encryption, strict segregation of duties, and continuous audit verification.

AICPA SSAE 18
SOC 1 Type II Certified
Audited by Vies Consulting LLC
AES-256 & TLS 1.3
End-to-End Encryption
At rest and in-transit data
AWS & GCP Cloud
Mumbai VPC Isolation
Private database subnets
Zero-Trust IAM
Least-Privilege RBAC
MFA & prompt offboarding

Core Security Architecture

Four Pillars of Enterprise Protection

Ambill embeds institutional-grade security, data protection, and process validation directly into every step of our finance automation stack.

Transaction Integrity

Automated input schema validations on GST numbers, quantities, and calculation bounds. Enforced segregation of duties across transaction drafts, submissions, and approvals.

Immutable audit trails

Military-Grade Encryption

All relational database disks (PostgreSQL RDS & Cloud SQL) and object storage (S3) are encrypted with AES-256-GCM. All network traffic is encrypted over TLS 1.2/1.3.

Zero plaintext storage

Least-Privilege RBAC

Strict role-based access control, enforced Multi-Factor Authentication (MFA) for cloud consoles, and automated access revocation upon employee offboarding.

Zero direct DB access

24/7 Availability & DR

Automated cloud snapshots, 8-year compliant retention, committed 24-hour RPO/RTO disaster recovery targets, and multi-zone AWS and GCP Mumbai VPC architecture.

Continuous CloudWatch alerts
OFFICIAL AUDIT ATTESTATION SUMMARY

SOC 1 Type II Compliance Report
Independent Auditor's Attestation

Independent CPA firm Vies Consulting LLC (CPA Firm # WY-1203) conducted an examination of the design and operating effectiveness of Ambill's internal controls over financial reporting (ICFR) under AICPA SSAE 18 standards.

Audit Period
Apr 1, 2025 to Mar 31, 2026
Report Valid through Apr 30, 2027
Audit Opinion
Unqualified / Clean Opinion
Controls Operating Effectively
Systems in Scope
Ambill Platform
AR, AP, Invoicing & Reconciliation
Hosting Region
AWS & GCP Mumbai, India
Multi-AZ Encrypted Datastores
Contact Compliance Officer
SOC
AICPA SSAE 18
Service Organization Controls
VERIFIED
Organization:Modulus Technologies LLP
Platform:Ambill Financial AI
Standard:SOC 1 Type II (SSAE 18)
Audit Scope:GITC & Transaction Processing
Auditor:Vies Consulting LLC
CPA Registration:Firm # WY-1203
The controls tested were suitably designed and operating effectively throughout the audited period.

Audited Control Framework

In-Depth Review of Our Security & Operational Controls

Explore how Ambill satisfies comprehensive trust criteria across applications, databases, cloud infrastructure, and operational processes.

Encryption at Rest (AES-256-GCM)

All customer data, relational databases (AWS RDS & GCP Cloud SQL), file storage (Amazon S3), and automated backups are encrypted at rest using 256-bit Advanced Encryption Standard (AES-256-GCM).

Encryption in Transit (TLS 1.2 / TLS 1.3)

All communication between client browsers, APIs, and microservices is enforced over HTTPS with TLS 1.2 and TLS 1.3 protocols, modern cipher suites, and SHA-2 signatures.

Authentication & Cryptographic Hashing

Credentials are protected with cryptographic salt hashing. Ambill also supports Single Sign-On (SSO) with enterprise Identity Providers via short-lived JWT tokens.

Endpoint Device Security

All engineer and operational devices enforce operating system full-disk encryption and automated security patching managed via ManageEngine MDM.

Collaborative Governance

Shared Responsibility Matrix

Security is a shared commitment between Ambill, our underlying cloud infrastructure providers, and customer organizations.

Ambill Platform

APPLICATION & DATA LAYER

  • Transaction schema validations & calculation accuracy
  • AES-256 at-rest and TLS 1.3 in-transit encryption
  • Role-based access control & workflow segregation
  • Immutable user activity and audit logging
  • Secure SDLC, locked master branch, and OWASP testing

AWS & GCP Cloud

PHYSICAL & INFRASTRUCTURE LAYER

  • Physical and biometric data center security in Mumbai
  • Hardware resilience, power redundancy, and fire safety
  • DDoS mitigation and network infrastructure defenses
  • Virtual Private Cloud (VPC) isolation and hypervisor security
  • Managed database automatic patching & snapshot persistence

Customer Organization

USER ACCESS & WORKFLOWS

  • Assigning appropriate RBAC roles to internal staff
  • Promptly de-provisioning offboarded employees
  • Reviewing and authorizing financial transactions
  • Protecting corporate credentials & enforcing password policies
  • Maintaining secure API connector credentials (Zoho/Tally/SAP)
FREQUENTLY ASKED QUESTIONS

Questions About Security & Compliance

Get answers to the most common questions asked by enterprise security, finance, and audit teams.

Ambill (by Modulus Technologies LLP) has successfully completed its SOC 1 Type II examination in accordance with AICPA SSAE 18 standards. The examination was performed by independent CPA firm Vies Consulting LLC (Firm # WY-1203) covering the period April 1, 2025 to March 31, 2026, valid through April 30, 2027. The independent auditor confirmed that our control objectives relating to internal controls over financial reporting were suitably designed and operating effectively.
ENTERPRISE-GRADE TRUST

Ready to review our complete SOC 1 Type II compliance package?

Our compliance team is ready to share our full auditor's report under NDA, provide technical architecture overviews, and respond to your vendor risk assessment questionnaires.