Our security, availability, and privacy commitments, independently examined under SOC 2 Type II across a continuous six month period.
Amber Connect Jamaica Limited provides AI-powered GPS vehicle tracking, fleet management, and telematics solutions to businesses, government agencies, and individual vehicle owners. Because our platform processes vehicle telemetry, GPS location, and driver behaviour data, we hold ourselves to a structured, standards driven security program that has been independently examined under SOC 2 Type II.
Our approach is built on all five trust principles, including Security, Availability, Processing Integrity, Confidentiality, and Privacy. These commitments are defined in our customer agreements, data processing agreements, terms of use, and operational policies.
To support these principles, we implement key security controls across identity and access management, infrastructure protection, vulnerability management, monitoring and incident response, secure development, business continuity, risk management, third party governance, data protection, and encryption.
SOC 2 Type II sets the requirements for effective internal controls across the Trust Principles of Security, Availability, Processing Integrity, Confidentiality, and Privacy. Amber Connect has been independently examined against all five, with controls tested for both suitability of design and operating effectiveness across the period 1 February 2026 to 31 July 2026.
The examination covered the Amber Connect Processing System: production and supporting non-production environments, the underlying cloud infrastructure, core application and service delivery components, and the systems used to store and process enterprise client data. It also extended to platform operations, incident management, change management, access management, and backup and recovery.
Systems are protected against unauthorised access, disclosure, and damage through role based access control, enforced multi-factor authentication, hardened managed devices, and continuous monitoring.
Infrastructure is designed for resilience with multi-region redundancy, uptime monitoring with automated alerting, automated backups, and a business continuity plan with defined recovery objectives.
Vehicle telemetry is enriched, validated, and delivered without loss, delay, or corruption. Syntactic and semantic validation, spot checks, and documented acceptance testing underpin all processing commitments.
Information designated confidential is protected with encryption at rest and in transit, need-to-know access subject to periodic review, data loss prevention, and confidentiality agreements binding every employee and contractor.
Personal data is collected, used, retained, and disposed of per our published privacy policy, the GDPR, and Jamaica's Data Protection Act, with documented procedures for access, rectification, restriction, and erasure.
Access is granted on a least-privilege basis, tied to job role and business need, with role based access control and multi-factor authentication enforced across systems and accounts. Access is provisioned on joining, reviewed on a regular cycle, and revoked promptly on departure or role change.
Employee devices are centrally managed and hardened, with endpoint detection and response, data loss prevention, mandatory full-disk encryption, removable media blocking, and web filtering. Perimeter traffic is filtered and inspected, and remote access requires an encrypted VPN with MFA.
A risk-based programme identifies, assesses, and remediates weaknesses across infrastructure and applications. Findings come from regular internal scanning and annual third-party penetration tests, and are prioritised by severity and tracked to closure.
Security events across endpoints, network devices, and cloud systems are aggregated and reviewed centrally, supported by intrusion detection and prevention. Our incident response process covers triage, communication, remediation, and root cause analysis.
A documented secure development methodology governs design, coding, testing, and deployment. Changes pass through a controlled pipeline with peer review, staging tests, version control, approval, and rollback procedures, with functional and acceptance testing before release.
A formal business continuity and disaster recovery plan defines recovery time and recovery point objectives. Critical data is backed up automatically across redundant multi-region infrastructure with encryption enforced, alerting on failure, and regular restoration testing.
A documented risk assessment and treatment plan covers data security, regulatory obligations, vendor dependencies, and technology risks, with defined operational priorities. Senior management incorporates the results into decision-making and resourcing.
Service providers and subservice organisations are monitored through contractual arrangements, periodic reviews, and oversight activities. Independent assurance reports from our cloud provider are reviewed annually.
Data, personnel, devices, systems, and facilities are managed under a documented asset management policy, with handling and access controls applied by sensitivity. Data is retained only as long as contractual or regulatory obligations require, then securely disposed of.
Encryption standards are applied across the data lifecycle under a formal cryptography policy. Cloud storage and managed databases are encrypted, endpoints and servers use full-disk encryption, and data in transit is secured with modern TLS. Keys are managed under policy.
The in-scope system is hosted by Amazon Web Services in the United States. AWS is responsible for physical and environmental security of the data centres hosting our production infrastructure. We review their SOC 2 Type II and ISO 27001 reports annually.
Kuya Technologies supports software design, development, testing, maintenance, and technical operations under Amber Connect's policies, standards, and oversight. Amber Connect retains ownership, governance, and accountability for the security and privacy of the service.
Manage your application accounts and available security settings, safeguard user IDs and passwords, review access rights periodically, and revoke access promptly for terminated or reassigned personnel.
Define acceptable data types for entry into the system in line with your classification and privacy requirements, transmit over secure or encrypted channels, and safeguard system-generated outputs and reports.
Notify Amber Connect promptly if you discover or suspect an incident involving our services, and act on our communications about platform changes that may affect security or availability.
Deploy endpoint protection on all devices used to access Amber Connect's services, and maintain independent business continuity and disaster recovery plans for your own environments.
The full SOC 2 Type II report, including the description of the Amber Connect Processing System and the auditor's tests of controls and results, is available on request.
To gain access to the report, please contact privacy@myambergroup.com. Include your organisation, your relationship to Amber Connect, your name and role, and the reason for the request.
Contact privacy@myambergroup.com
Use of the report is restricted to Amber Connect, user entities of the Amber Connect Processing System, business partners subject to risks arising from interactions with the system, prospective user entities and business partners, practitioners providing services to those parties, and regulators with sufficient knowledge of the service and the inherent limitations of internal control. Unauthorised use, reproduction, or distribution of the report, in whole or in part, is strictly prohibited.