About This Trust Center
Amber OnTime is a ride-hailing and transportation platform operating in Jamaica, connecting riders with Captains through a mobile app offering ride booking and dispatch, real-time GPS ride tracking, in-app fare payment, and an in-app emergency response button. It is built and operated by Amber Innovations Limited, the software development and technology arm of the Amber Group of Companies.
Every ride generates sensitive information: where you were picked up, where you went, when you travelled, and how you paid. Amber Innovations holds a SOC 2 Type II attestation over the Amber Innovations Processing System, of which the Amber OnTime platform is an in-scope component. An independent auditor examined how our controls actually operated across a continuous six month period, rather than certifying a single moment in time.
The attestation covers all five trust principles, including Security, Availability, Processing Integrity, Confidentiality, and Privacy, supported by controls across identity and access management, infrastructure protection, vulnerability management, monitoring and incident response, secure development, business continuity, risk management, third party governance, data protection, and encryption.
Certification Details

SOC 2 Type II
SOC 2 Type II sets the requirements for effective internal controls across the Trust Principles of Security, Availability, Processing Integrity, Confidentiality, and Privacy. Amber Innovations, which operates Amber OnTime, has been independently examined against all five, with controls tested for both suitability of design and operating effectiveness across the period 1 February 2026 to 31 July 2026.
Scope of the Examination
The examination covered the Amber Innovations Processing System, with Amber OnTime named as an in-scope platform. It spans production and supporting non-production environments, the underlying cloud infrastructure, core application and service delivery components, and the systems used to store and process ride and customer data, along with platform operations, incident management, change management, access management, and backup and recovery.
Independently Verified Trust Principles
Security
01Systems are protected against unauthorised access, disclosure, and damage through role based access control, enforced multi-factor authentication, hardened managed devices, and continuous monitoring.
Availability
02Infrastructure is designed for resilience with multi-region redundancy, uptime monitoring with automated alerting, automated backups, and a business continuity plan with defined recovery objectives.
Processing Integrity
03Ride records, trip tracking, and fare calculations are processed completely, accurately, and on time. Syntactic and semantic validation, manual spot checks, and reconciliation across system interfaces underpin all processing commitments.
Confidentiality
04Rider and Captain information is protected with encryption at rest and in transit, need-to-know access subject to periodic review, data loss prevention, and confidentiality agreements binding every employee and contractor.
Privacy
05Ride history, location, and personal data are collected, used, retained, and disposed of per our published privacy policy, the GDPR, and Jamaica's Data Protection Act, with documented procedures for the rights to access, rectify, restrict processing, and request erasure.
Our Security Controls
Identity & Access Control
01Access is granted on a least-privilege basis, tied to job role and business need, with role based access control and multi-factor authentication enforced across systems and accounts. Access is provisioned on joining, reviewed on a regular cycle, and revoked promptly on departure or role change.
Endpoint & Network Protection
02Employee devices are centrally managed and hardened, with endpoint detection and response, data loss prevention, mandatory full-disk encryption, removable media blocking, and web filtering. Perimeter traffic is filtered and inspected, and remote access requires an encrypted VPN with MFA.
Vulnerability Management
03A risk-based programme identifies, assesses, and remediates weaknesses across infrastructure and applications. Findings come from regular internal scanning and annual third-party penetration tests, and are prioritised by severity and tracked to closure.
Monitoring & Incident Response
04Security events across endpoints, network devices, and cloud systems are aggregated and reviewed centrally through a SIEM platform, supported by intrusion detection and prevention and continuous uptime monitoring. Our incident response process covers triage, communication, remediation, and root cause analysis.
Secure Development & Change
05A documented Secure Software Development Methodology governs design, coding, testing, and deployment. Changes pass through a controlled CI/CD pipeline with peer code review, staging tests, version control, strict approval and audit mechanisms, and documented rollback procedures.
Continuity & Data Resilience
06A formal business continuity and disaster recovery plan defines recovery time and recovery point objectives. Critical data is backed up automatically across redundant multi-region infrastructure with encryption enforced, alerting on failure, and regular restoration testing.
Risk Management
07A documented risk assessment and treatment plan covers data security, regulatory obligations, vendor dependencies, and technology risks, with defined operational priorities. Senior management incorporates the results into decision-making and resourcing.
Vendor & Third-Party Risk
08Service providers and subservice organisations are monitored through contractual arrangements, periodic reviews, and oversight activities. Independent assurance reports from our cloud provider are reviewed annually.
Data Classification & Retention
09Data, personnel, devices, systems, and facilities are managed under a documented asset management policy, with handling and access controls applied by sensitivity. Data is retained only as long as contractual or regulatory obligations require, then securely disposed of.
Cryptography & Encryption
10Encryption standards are applied across the data lifecycle under a formal cryptography policy. Cloud storage and managed databases are encrypted, endpoints and servers use full-disk encryption, and data in transit is secured with modern TLS. Keys are managed under policy.
Subservice Organisations
Cloud Infrastructure
01The in-scope system is hosted by Amazon Web Services in the United States, using multi-region deployments for high availability. AWS is responsible for physical and environmental security of the data centres hosting our production infrastructure. We review their SOC 2 Type II and ISO 27001 reports annually.
Extended Engineering
02Kuya Technologies supports software design, development, testing, maintenance, and technical operations under Amber Innovations' policies, standards, and oversight. Amber Innovations retains ownership, governance, and accountability for the security and privacy of the service.
Corporate Account Responsibilities
Account & Access Administration
01Manage your application accounts and available security settings, safeguard user IDs and passwords, review access rights periodically, and revoke access promptly for terminated or reassigned personnel.
Data Handling & Transmission
02Define acceptable data types for entry into the Amber OnTime system in line with your classification and privacy requirements, transmit over secure or encrypted channels, and safeguard system-generated trip reports and outputs.
Incident & Change Awareness
03Notify Amber OnTime promptly if you discover or suspect an incident involving our services, and act on our communications about platform changes that may affect security or availability.
Endpoint & Continuity Readiness
04Deploy endpoint protection on all devices used to access Amber OnTime's corporate services, and maintain independent business continuity and disaster recovery plans for your own environments.
Access to the SOC 2 Type II Report
Requesting the Report
The full SOC 2 Type II report, including the description of the Amber Innovations Processing System and the auditor's tests of controls and results, is available on request. It is most relevant to corporate and enterprise customers evaluating Amber OnTime for their organisation.
To gain access to the report, please contact privacy@myambergroup.com. Include your organisation, your relationship to Amber OnTime, your name and role, and the reason for the request.
Contact privacy@myambergroup.com
Use of the report is restricted to Amber Innovations, user entities of the Amber Innovations Processing System including Amber OnTime, business partners subject to risks arising from interactions with the system, prospective user entities and business partners, practitioners providing services to those parties, and regulators with sufficient knowledge of the service and the inherent limitations of internal control. Unauthorised use, reproduction, or distribution of the report, in whole or in part, is strictly prohibited.