About This Trust Center
Amber Innovations Limited is the software development and technology arm of the Amber Group of Companies, delivering end-to-end custom software, cloud, and AI-driven solutions across the Group's business lines and to third-party clients globally. Because our platforms process payment and transaction data, ride and location data, and personal information, we hold ourselves to a structured, standards driven security program that has been independently examined under SOC 2 Type II.
Our approach is built on all five trust principles, including Security, Availability, Processing Integrity, Confidentiality, and Privacy. These commitments are defined in our customer agreements, data processing agreements, terms of use, and operational policies.
To support these principles, we implement key security controls across identity and access management, infrastructure protection, vulnerability management, monitoring and incident response, secure development, business continuity, risk management, third party governance, data protection, and encryption.
Certification Details

SOC 2 Type II
SOC 2 Type II sets the requirements for effective internal controls across the Trust Principles of Security, Availability, Processing Integrity, Confidentiality, and Privacy. Amber Innovations has been independently examined against all five, with controls tested for both suitability of design and operating effectiveness across the period 1 February 2026 to 31 July 2026.
Scope of the Examination
The examination covered the Amber Innovations Processing System supporting two in-scope platforms: Amber Pay, a digital payment platform, and Amber OnTime, a ride-hailing and transportation platform. It spans production and supporting non-production environments, the underlying cloud infrastructure, core application and service delivery components, and the systems used to store and process data for enterprise clients, along with platform operations, incident management, change management, access management, and backup and recovery.
Independently Verified Trust Principles
Security
01Systems are protected against unauthorised access, disclosure, and damage through role based access control, enforced multi-factor authentication, hardened managed devices, and continuous monitoring.
Availability
02Infrastructure is designed for resilience with multi-region redundancy, uptime monitoring with automated alerting, automated backups, and a business continuity plan with defined recovery objectives.
Processing Integrity
03Data is enriched, validated, and delivered without loss, delay, or corruption. Syntactic and semantic validation, manual spot checks, and reconciliation reports across webhook, API, and batch exports underpin all processing commitments.
Confidentiality
04Information designated confidential is protected with encryption at rest and in transit, need-to-know access subject to periodic review, data loss prevention, and confidentiality agreements binding every employee and contractor.
Privacy
05Personal data is collected, used, retained, and disposed of per our published privacy policy, the GDPR, and Jamaica's Data Protection Act, with documented procedures for access, rectification, restriction, and erasure.
Our Security Controls
Identity & Access Control
01Access is granted on a least-privilege basis, tied to job role and business need, with role based access control and multi-factor authentication enforced across systems and accounts. Access is provisioned on joining, reviewed on a regular cycle, and revoked promptly on departure or role change.
Endpoint & Network Protection
02Employee devices are centrally managed and hardened, with endpoint detection and response, data loss prevention, mandatory full-disk encryption, removable media blocking, and web filtering. Perimeter traffic is filtered and inspected, and remote access requires an encrypted VPN with MFA.
Vulnerability Management
03A risk-based programme identifies, assesses, and remediates weaknesses across infrastructure and applications. Findings come from regular internal scanning and annual third-party penetration tests, and are prioritised by severity and tracked to closure.
Monitoring & Incident Response
04Security events across endpoints, network devices, and cloud systems are aggregated and reviewed centrally through a SIEM platform, supported by intrusion detection and prevention and continuous uptime monitoring. Our incident response process covers triage, communication, remediation, and root cause analysis.
Secure Development & Change
05A documented Secure Software Development Methodology governs design, coding, testing, and deployment. Changes pass through a controlled CI/CD pipeline with peer code review, staging tests, version control, strict approval and audit mechanisms, and documented rollback procedures.
Continuity & Data Resilience
06A formal business continuity and disaster recovery plan defines recovery time and recovery point objectives. Critical data is backed up automatically across redundant multi-region infrastructure with encryption enforced, alerting on failure, and regular restoration testing.
Risk Management
07A documented risk assessment and treatment plan covers data security, regulatory obligations, vendor dependencies, and technology risks, with defined operational priorities. Senior management incorporates the results into decision-making and resourcing.
Vendor & Third-Party Risk
08Service providers and subservice organisations are monitored through contractual arrangements, periodic reviews, and oversight activities. Independent assurance reports from our cloud provider are reviewed annually.
Data Classification & Retention
09Data, personnel, devices, systems, and facilities are managed under a documented asset management policy, with handling and access controls applied by sensitivity. Data is retained only as long as contractual or regulatory obligations require, then securely disposed of.
Cryptography & Encryption
10Encryption standards are applied across the data lifecycle under a formal cryptography policy. Cloud storage and managed databases are encrypted, endpoints and servers use full-disk encryption, and data in transit is secured with modern TLS. Keys are managed under policy.
Subservice Organisations
Cloud Infrastructure
01The in-scope system is hosted by Amazon Web Services in the United States, using multi-region deployments for high availability. AWS is responsible for physical and environmental security of the data centres hosting our production infrastructure. We review their SOC 2 Type II and ISO 27001 reports annually.
Extended Engineering
02Kuya Technologies supports software design, development, testing, maintenance, and technical operations under Amber Innovations' policies, standards, and oversight. Amber Innovations retains ownership, governance, and accountability for the security and privacy of the service.
Customer Responsibilities
Account & Access Administration
01Manage your application accounts and available security settings, safeguard user IDs and passwords, review access rights periodically, and revoke access promptly for terminated or reassigned personnel.
Data Handling & Transmission
02Define acceptable data types for entry into the Amber Innovations system in line with your classification and privacy requirements, transmit over secure or encrypted channels, and safeguard system-generated outputs and reports.
Incident & Change Awareness
03Notify Amber Innovations promptly if you discover or suspect an incident involving our services, and act on our communications about platform changes that may affect security or availability.
Endpoint & Continuity Readiness
04Deploy endpoint protection on all devices used to access Amber Innovations' services, and maintain independent business continuity and disaster recovery plans for your own environments.
Access to the SOC 2 Type II Report
Requesting the Report
The full SOC 2 Type II report, including the description of the Amber Innovations Processing System and the auditor's tests of controls and results, is available on request.
To gain access to the report, please contact privacy@myambergroup.com. Include your organisation, your relationship to Amber Innovations, your name and role, and the reason for the request.