Amber Connect Jamaica Limited

Trust Center

Our security, availability, and privacy commitments, independently examined under SOC 2 Type II across a continuous six month period.

About This Trust Center

Amber Connect Jamaica Limited provides AI-powered GPS vehicle tracking, fleet management, and telematics solutions to businesses, government agencies, and individual vehicle owners. Because our platform processes vehicle telemetry, GPS location, and driver behaviour data, we hold ourselves to a structured, standards driven security program that has been independently examined under SOC 2 Type II.

Our approach is built on all five trust principles, including Security, Availability, Processing Integrity, Confidentiality, and Privacy. These commitments are defined in our customer agreements, data processing agreements, terms of use, and operational policies.

To support these principles, we implement key security controls across identity and access management, infrastructure protection, vulnerability management, monitoring and incident response, secure development, business continuity, risk management, third party governance, data protection, and encryption.

Certification Details

SOC 2 Type II

SOC 2 Type II sets the requirements for effective internal controls across the Trust Principles of Security, Availability, Processing Integrity, Confidentiality, and Privacy. Amber Connect has been independently examined against all five, with controls tested for both suitability of design and operating effectiveness across the period 1 February 2026 to 31 July 2026.

Scope of the Examination

The examination covered the Amber Connect Processing System: production and supporting non-production environments, the underlying cloud infrastructure, core application and service delivery components, and the systems used to store and process enterprise client data. It also extended to platform operations, incident management, change management, access management, and backup and recovery.

Independently Verified Trust Principles

Security01

Systems are protected against unauthorised access, disclosure, and damage through role based access control, enforced multi-factor authentication, hardened managed devices, and continuous monitoring.

Availability02

Infrastructure is designed for resilience with multi-region redundancy, uptime monitoring with automated alerting, automated backups, and a business continuity plan with defined recovery objectives.

Processing Integrity03

Vehicle telemetry is enriched, validated, and delivered without loss, delay, or corruption. Syntactic and semantic validation, spot checks, and documented acceptance testing underpin all processing commitments.

Confidentiality04

Information designated confidential is protected with encryption at rest and in transit, need-to-know access subject to periodic review, data loss prevention, and confidentiality agreements binding every employee and contractor.

Privacy05

Personal data is collected, used, retained, and disposed of per our published privacy policy, the GDPR, and Jamaica's Data Protection Act, with documented procedures for access, rectification, restriction, and erasure.

Our Security Controls

Identity & Access Control01

Access is granted on a least-privilege basis, tied to job role and business need, with role based access control and multi-factor authentication enforced across systems and accounts. Access is provisioned on joining, reviewed on a regular cycle, and revoked promptly on departure or role change.

Endpoint & Network Protection02

Employee devices are centrally managed and hardened, with endpoint detection and response, data loss prevention, mandatory full-disk encryption, removable media blocking, and web filtering. Perimeter traffic is filtered and inspected, and remote access requires an encrypted VPN with MFA.

Vulnerability Management03

A risk-based programme identifies, assesses, and remediates weaknesses across infrastructure and applications. Findings come from regular internal scanning and annual third-party penetration tests, and are prioritised by severity and tracked to closure.

Monitoring & Incident Response04

Security events across endpoints, network devices, and cloud systems are aggregated and reviewed centrally, supported by intrusion detection and prevention. Our incident response process covers triage, communication, remediation, and root cause analysis.

Secure Development & Change05

A documented secure development methodology governs design, coding, testing, and deployment. Changes pass through a controlled pipeline with peer review, staging tests, version control, approval, and rollback procedures, with functional and acceptance testing before release.

Continuity & Data Resilience06

A formal business continuity and disaster recovery plan defines recovery time and recovery point objectives. Critical data is backed up automatically across redundant multi-region infrastructure with encryption enforced, alerting on failure, and regular restoration testing.

Risk Management07

A documented risk assessment and treatment plan covers data security, regulatory obligations, vendor dependencies, and technology risks, with defined operational priorities. Senior management incorporates the results into decision-making and resourcing.

Vendor & Third-Party Risk08

Service providers and subservice organisations are monitored through contractual arrangements, periodic reviews, and oversight activities. Independent assurance reports from our cloud provider are reviewed annually.

Data Classification & Retention09

Data, personnel, devices, systems, and facilities are managed under a documented asset management policy, with handling and access controls applied by sensitivity. Data is retained only as long as contractual or regulatory obligations require, then securely disposed of.

Cryptography & Encryption10

Encryption standards are applied across the data lifecycle under a formal cryptography policy. Cloud storage and managed databases are encrypted, endpoints and servers use full-disk encryption, and data in transit is secured with modern TLS. Keys are managed under policy.

Subservice Organisations

Cloud Infrastructure01

The in-scope system is hosted by Amazon Web Services in the United States. AWS is responsible for physical and environmental security of the data centres hosting our production infrastructure. We review their SOC 2 Type II and ISO 27001 reports annually.

Extended Engineering02

Kuya Technologies supports software design, development, testing, maintenance, and technical operations under Amber Connect's policies, standards, and oversight. Amber Connect retains ownership, governance, and accountability for the security and privacy of the service.

Customer Responsibilities

Account & Access Administration01

Manage your application accounts and available security settings, safeguard user IDs and passwords, review access rights periodically, and revoke access promptly for terminated or reassigned personnel.

Data Handling & Transmission02

Define acceptable data types for entry into the system in line with your classification and privacy requirements, transmit over secure or encrypted channels, and safeguard system-generated outputs and reports.

Incident & Change Awareness03

Notify Amber Connect promptly if you discover or suspect an incident involving our services, and act on our communications about platform changes that may affect security or availability.

Endpoint & Continuity Readiness04

Deploy endpoint protection on all devices used to access Amber Connect's services, and maintain independent business continuity and disaster recovery plans for your own environments.

Access to the SOC 2 Type II Report

Requesting the Report

The full SOC 2 Type II report, including the description of the Amber Connect Processing System and the auditor's tests of controls and results, is available on request.

To gain access to the report, please contact privacy@myambergroup.com. Include your organisation, your relationship to Amber Connect, your name and role, and the reason for the request.

Contact privacy@myambergroup.com

Use of the report is restricted to Amber Connect, user entities of the Amber Connect Processing System, business partners subject to risks arising from interactions with the system, prospective user entities and business partners, practitioners providing services to those parties, and regulators with sufficient knowledge of the service and the inherent limitations of internal control. Unauthorised use, reproduction, or distribution of the report, in whole or in part, is strictly prohibited.