Security & compliance
Built for regulated distribution, secured accordingly.
How does Amoura keep distribution data secure?
Amoura is built for medical & health distributors who handle regulated, high-value stock. Access is role-based on every action. Users sign in with two-factor codes or a passkey. Approvals and financial actions go into an audit log, every record is scoped to its company, requests are rate-limited, orders need dual sign-off, and VAT/TRN invoices are raised from delivered orders.
Role-based access
Every action, approval and financial change is checked against the user's role.
Two-factor sign-in
Authenticator-app codes (TOTP) and passkeys. A device can be trusted for 30 days so people aren't asked every time.
Audit log
Approvals, price changes and financial actions are logged with who, what and when. Admins can filter the log and export it.
Rate limiting
Sign-in and other sensitive requests are rate-limited to slow down abuse.
Company data kept apart
Every record belongs to one company and every query is scoped to it, so one company never sees another's data.
Dual sign-off on orders
Orders need manager and warehouse approval, and high-value orders also need the CEO or GM.
Expiry and licence tracking
Batch expiry is tracked on a compliance screen. Licences, permits, contracts and insurance are stored with expiry dates and marked as expiring 30 days ahead.
VAT/TRN records
Tax invoices carry your TRN and line-level VAT, raised from orders when they are marked delivered.
We list only what’s real, so you won’t see certifications here that Amoura doesn’t hold. Ask us about anything specific to your compliance needs.
Security questions
How does Amoura control who can see and change data?+
Access is role-based. Every action, approval and financial change is checked against the user's role, and each role has its own pages and permissions. Every record belongs to one company and every query is scoped to it, so one company never sees another's data.
Does Amoura support two-factor sign-in?+
Yes. Users sign in with authenticator-app codes (TOTP) or a passkey. A device can be trusted for 30 days so people are not asked every time.
Is there an audit log?+
Yes. Approvals, price changes and financial actions are logged with who, what and when. Admins can filter the log and export it.
Ready when you are
See how your data is handled.
Book a founder-led demo and we’ll walk your real workflow (orders, approvals, inventory, finance) on the system, not a slide deck.
