1What this covers
This overview covers the Amend web application, the Amend phone app, the client portal, DocuMend electronic signatures and Mend, the AI assistant. Optional integrations are named on the Service providers list. The Privacy Policy also explains information collected through Amend's websites and marketing.
2Where information is processed
| Part of the service | Provider | What it does |
|---|---|---|
| Application and databases | Google Cloud, us-west1 (United States) | Runs Amend and stores its databases |
| Uploaded files | Cloudflare R2 | Stores files you upload, after Amend encrypts them |
| Network edge | Cloudflare | Carries and filters traffic to Amend |
| AI features | Google Cloud Vertex AI | Runs the models behind Mend and other AI features |
| Resend | Delivers account emails, invoices and notifications sent from Amend | |
| Payments | Stripe | Takes card payments into your own Stripe account |
| Bank connections | Plaid | Connects a bank account, only if you connect one |
3Who is responsible for what
- Google Cloud and Cloudflare operate the physical infrastructure Amend uses: buildings, power and hardware. They publish their own independent security reports; those reports cover their services, not Amend's application.
- Amend configures and operates its application, its access controls and its application-level encryption.
- Services your business chooses to connect receive the information those features need.
4Keeping businesses apart
- For signed-in requests, Amend determines the business from the authenticated session and checks access on the server.
- Each business's sensitive data is encrypted with its own business-specific key. The business's identity is bound into each encrypted value, so a value copied to another business does not open.
- Automated tests place marked data in one business and try to read it while signed in as another.
5Encryption and keys
In transit
Connections to Amend use TLS, and browsers are told to use encrypted connections to Amend only, for one year, including subdomains.
At rest
- Sensitive fields, such as contact details, signatures, notes and credentials used to connect other services, are encrypted with AES-256-GCM before they are stored.
- Uploaded files are encrypted the same way before they are stored.
- Each business-specific key is derived with HKDF-SHA256 from a master secret that is not stored in Amend's source code.
Who manages the keys, and when data is readable
Amend manages the encryption keys. Customers do not hold their own keys. The application decrypts information when it is needed to provide the service. Some values used to find and sort records, such as dates, amounts and internal identifiers, remain readable inside the database; Google Cloud encrypts the underlying disks.
6Sign-in and roles
| Ways to sign in | Email and password, passkeys, Sign in with Google, Sign in with Apple |
|---|---|
| Two-step verification | Authenticator-app codes, available to every account |
| Failed attempts | After 8 failed attempts within 5 minutes, sign-in pauses for that account and network address |
| Session length | Up to 12 hours on the web; up to 30 days in the Amend phone app |
| When access changes | Changing a password, or a person's access, ends that person's other sessions |
| Roles | Owner, admin, office, sales, crew, subcontractor and accountant, checked on the server |
| Whole-business export | Owners and admins only; each export is recorded |
| Sign-in history | Kept for 180 days |
7Mend, the AI assistant
- Mend acts with the permissions of the person using it.
- Before Mend sends an invoice, takes a payment or contacts anyone outside your business, it asks for approval of that specific action.
- AI requests from your business run on Google Cloud Vertex AI. Amend does not use customer data to train AI models unless a company switches that on for itself, and does not give Google permission to train its models on it.
- We never benchmark you against another business: one customer’s data is never used to answer another’s question, and prices, margins and win rates are never pooled, compared or shared. A company can switch on letting its own corrections help train the assistant; it is off unless switched on, names and dollar amounts are stripped first, and prices are never included.
- Mend can keep short notes about how your business works. Before a note is saved, filters remove names, amounts and contact details; filters can miss information. Saved notes are encrypted for your business and can be reviewed, edited and deleted in Settings.
8Payments and bank connections
- With Stripe-hosted checkout, card details are entered directly on Stripe's pages. Amend receives payment status and transaction references.
- Payments from your clients go through your own Stripe account to your own bank. Amend does not hold your funds.
- Stripe payment messages are checked for a valid signature and a recent timestamp, and repeated messages are recognised so a payment is not processed twice.
- Bank connections run through Plaid. You sign in to your bank through Plaid, and Amend does not receive your bank username or password.
9Building and releasing the software
- Release checks include automated tests and a scan for credentials accidentally written into the code.
- Third-party software Amend depends on is checked daily against public lists of known vulnerabilities.
- Security tests cover separation between businesses, removal of a team member's access, and files that could run code in a browser.
10Handling security findings
Amend records security findings as numbered issues, each with its evidence, its fix and the check that confirms the fix. A statement about a control is not published while a finding makes it inaccurate. Suspected security issues can be reported to [email protected].
11Monitoring
An automated monitor checks the production server's health, disk and memory, unexpected open network ports and error patterns, and alerts us when something is wrong.
12Backups and recovery
- Databases are copied every hour to a separate storage bucket with its own credentials, which the application does not use.
- The production server's disk is snapshotted every day.
- A scheduled job checks that backups exist and match what was recorded. A server snapshot restore was rehearsed on 9 September 2026.
- Sensitive fields remain encrypted inside backups.
13Security incidents
Amend keeps a written incident response plan. If we confirm a breach affecting personal data we process for your business, we will notify you without undue delay and in any event within 72 hours of confirming it, describe what we know, and provide updates as the investigation continues.
14Export and deletion
- An owner or admin can export the business's data at any time, including uploaded files and signed documents. Other roles cannot export a whole business.
- When a trial ends or a subscription is cancelled, the business has 5 days to export.
- After an account is closed, the owner has 14 days to export. The data is then removed from the live service. Copies can remain in backups.
- Deleted files stay in the trash for 30 days.
- Sign-in history is kept for 180 days, and source material used to process receipts and documents for 180 days.
- Payroll, wage and tax records are kept for the period the law requires.
15What you control
- Turn on two-step verification, or use a passkey, for every owner and admin.
- Give each person the lowest role that lets them do their work.
- Remove people from your business the day they leave.
- Contact [email protected] straight away if you think someone has signed in to your account.