Built to be relied on by regulated institutions.
Banks, lenders and funds answer to regulators, auditors and customers. Everything we build is designed to make those conversations easier.
Our design principles
Independent by design
Our calculation engine shares no code or logic with the systems it checks. Independence is what makes a control a control.
Deterministic where money is involved
Amounts are calculated by tested, deterministic code with exact decimal arithmetic. Language models never decide a number.
People approve what matters
Amortis investigates and proposes. A named person approves any action that changes a customer's money or a regulatory record.
Evidence by default
Each run records its inputs, rule versions, results and approvals, so any figure can be traced and reproduced later.
Least data, least access
We ask only for the data a task needs, read it without write access, and de-identify it for pilots.
Your environment, your choice
Products can run inside your own cloud environment, so your data does not leave it.
Designed with your obligations in mind
These are the frameworks risk and compliance teams most often raise with us, and how Amortis can support the work they require.
| Framework | How Amortis can support it |
|---|---|
| APRA CPS 230, Operational Risk Management | An independent, repeatable check over loan calculations, with records of each run and what it found. |
| APRA CPS 234, Information Security | Read-only access, minimal data, the option to run in your own environment, and documentation for your service-provider review. |
| ASIC RG 277, Consumer remediation | Identifying affected customers, calculating refunds and compensation transparently, and keeping the working. |
| ASIC RG 78, Breach reporting | Establishing the scope and facts of an issue quickly, so reporting decisions are made on evidence. |
Amortis supports your controls. It is not legal or compliance advice, and using it does not by itself make an institution compliant with any framework. Responsibility for compliance stays with your institution. We share our security documentation under a non-disclosure agreement as part of procurement.
Data handling
- EncryptionData is encrypted in transit and at rest.
- LocationYour own environment, or Australian hosting for Everlant-run services.
- RetentionPilot data is deleted at the end of the engagement, with written confirmation.
- AI modelsYour data is never used to train AI models, ours or anyone else's.
- AccessNamed people only, with every access logged.
Bring your risk and security teams into the conversation early.
We are happy to walk through our architecture, controls and data handling with them before any pilot starts.
Contact us