Built to be relied on by regulated institutions.

Banks, lenders and funds answer to regulators, auditors and customers. Everything we build is designed to make those conversations easier.

Our design principles

Independent by design

Our calculation engine shares no code or logic with the systems it checks. Independence is what makes a control a control.

Deterministic where money is involved

Amounts are calculated by tested, deterministic code with exact decimal arithmetic. Language models never decide a number.

People approve what matters

Amortis investigates and proposes. A named person approves any action that changes a customer's money or a regulatory record.

Evidence by default

Each run records its inputs, rule versions, results and approvals, so any figure can be traced and reproduced later.

Least data, least access

We ask only for the data a task needs, read it without write access, and de-identify it for pilots.

Your environment, your choice

Products can run inside your own cloud environment, so your data does not leave it.

Designed with your obligations in mind

These are the frameworks risk and compliance teams most often raise with us, and how Amortis can support the work they require.

FrameworkHow Amortis can support it
APRA CPS 230, Operational Risk ManagementAn independent, repeatable check over loan calculations, with records of each run and what it found.
APRA CPS 234, Information SecurityRead-only access, minimal data, the option to run in your own environment, and documentation for your service-provider review.
ASIC RG 277, Consumer remediationIdentifying affected customers, calculating refunds and compensation transparently, and keeping the working.
ASIC RG 78, Breach reportingEstablishing the scope and facts of an issue quickly, so reporting decisions are made on evidence.

Amortis supports your controls. It is not legal or compliance advice, and using it does not by itself make an institution compliant with any framework. Responsibility for compliance stays with your institution. We share our security documentation under a non-disclosure agreement as part of procurement.

Data handling

  • EncryptionData is encrypted in transit and at rest.
  • LocationYour own environment, or Australian hosting for Everlant-run services.
  • RetentionPilot data is deleted at the end of the engagement, with written confirmation.
  • AI modelsYour data is never used to train AI models, ours or anyone else's.
  • AccessNamed people only, with every access logged.

Bring your risk and security teams into the conversation early.

We are happy to walk through our architecture, controls and data handling with them before any pilot starts.

Contact us