Executive Summary
AI-generated analysis for Amplitude
Amplitude (amplitude.com) is a digital analytics and AI analytics platform assessed at Risk Tier 3 (Moderate Risk) with a 94% confidence score, reflecting a vendor with meaningful security credentials and a long-established presence, alongside several documentation and transparency gaps that warrant attention before full deployment. Amplitude demonstrates a number of positive signals across its security posture:
Key Findings
- The domain has a 29-year established history, registered since 1996 and managed through enterprise registrar MarkMonitor, indicating organizational maturity.
- Infrastructure exposure is minimal, with only 2 open ports (80 and 443) and zero known CVEs — well below the SaaS industry average of 8–12 open ports, representing a tightly controlled attack surface.
- Domain reputation is clean across all threat intelligence databases, with no blacklist entries, no active malware URLs, and a zero abuse score on the primary IP.
- The vendor's AI data usage policy discloses third-party AI providers (OpenAI and Amazon Bedrock) and states that customer data is not retained after AI processing. Amplitude also contractually prohibits its AI partners from using customer data to train or improve their models, which is a positive and increasingly important commitment.
- SOC 2 Type II and ISO 27001 are claimed on the vendor's public trust page at https://amplitude.com/trust, and HIPAA compliance is referenced for applicable use cases. Several concerns require resolution before this vendor can be fully cleared for medium data access:
- Three certifications (SOC 2, ISO 27001, HIPAA) are vendor-attested on the trust page but could not be independently verified through public registries. Buyers must obtain the actual audit reports directly from the vendor.
- The subprocessor list at https://trust.amplitude.com/subprocessors appears to contain placeholder content with no individual subprocessors identified — a material gap for GDPR Article 28 compliance obligations.
- AI training data handling carries an opt-out classification under the more conservative interpretation, meaning customers on certain tiers or configurations may need to actively disable AI training to ensure data is not used for model improvement.
- The marketing site (amplitude.com) received a D+ grade on HTTP security headers, though this assessment applies to the public-facing site rather than the application endpoint (app.amplitude.com). Overall, Amplitude presents as a substantive, mature vendor with demonstrable security investments, but unresolved documentation gaps — particularly around subprocessor transparency and certification verification — prevent an unqualified approval at this time. A conditional engagement is appropriate pending receipt of current audit reports and a complete subprocessor disclosure.
Independence Statement
All evidence in this report was independently sourced from external data repositories, threat intelligence feeds, public registries, and web scanning tools without vendor participation or input.