Security Controls
Last Updated: July 10, 2026
This Security Controls document ("Document") describes the technical and organisational security measures implemented by Amber News and our affiliates (together, "Amber News", "we", "our", or "us") to protect Personal Data and ensure the integrity, availability, and confidentiality of our Services. This Document supplements our Privacy Policy.
Amber News implements reasonable and appropriate technical and organisational measures to secure and protect Personal Data against unauthorised access, disclosure, alteration, or destruction. These measures include encryption of data in transit and at rest, access controls, audit logging, and regular security assessments. The controls described herein are reviewed and updated periodically to reflect changes in our security posture, regulatory obligations, and threat landscape.
1. Governance and Policy Framework
Amber News maintains a comprehensive governance and policy framework to ensure that security, privacy, and operational standards are formally established, communicated, and enforced across the organisation. The following policies are established, approved by management, and reviewed at defined intervals:
- Information Security Policy. Comprehensive information security policy establishing the organisation's security objectives, principles, and commitment to protecting information assets. Reviewed and approved by management at defined intervals.
- Acceptable Usage Policy. Defines acceptable and prohibited use of organisational information systems, networks, and data. Ensures employees and contractors understand their responsibilities when using company resources.
- Code of Conduct Policy. Establishes standards of ethical behaviour and professional conduct expected of all employees, including adherence to legal requirements, confidentiality obligations, and organisational values.
- Data Protection and Privacy Policy. Governs the collection, processing, storage, and sharing of personal data in compliance with the General Data Protection Regulation (GDPR), the Digital Personal Data Protection Act, 2023 (DPDPA), and the Data Protection Act, 2020 of Jamaica. Outlines data subject rights and breach notification procedures.
- Privacy Policy on Website. Publicly accessible privacy policy detailing data collection practices, sub-processors, retention periods, international data transfers, and data subject rights across all applicable jurisdictions.
- List of Approved Policies and Procedures. Maintained register of all approved organisational policies and procedures with version history, approval dates, and review schedules to ensure document governance and availability.
- Availability of Policy Documents. All policy documents are made available to relevant stakeholders and employees. Policies are reviewed, updated, and distributed at defined intervals to ensure currency and awareness.
- Whistleblower Policy. Formal whistleblower policy enabling employees and stakeholders to report unethical conduct, security violations, or compliance concerns through protected channels without fear of retaliation.
- Management Roles and Responsibilities. Clear definition and assignment of security roles and responsibilities across management, including ownership of policies, risk management, incident response, and compliance oversight.
2. Access Management and Authentication
Amber News enforces strict access management and authentication controls to ensure that only authorised individuals can access systems, applications, and data. Access is granted on a least-privilege basis with formal approval workflows.
- Access Management Policy. Formal policy governing user access provisioning, de-provisioning, and periodic access reviews. All access to systems and data requires formal access request and approval. Access is provisioned based on job function and follows the principle of least privilege.
- Password Policy. Formal password policy defining complexity requirements, rotation schedules, storage standards, and handling procedures for all organisational credentials. The following technical controls are enforced:
- First-Time Password Change Required. Users are required to update their password upon first login before accessing the Services. This ensures that system-generated or administrator-set credentials are replaced with user-chosen secure passwords.
- Minimum 12-Character Password Requirement. All user passwords must be at least 12 characters in length, enforcing strong password complexity to mitigate brute-force and credential stuffing attacks.
- Password History Enforcement (Last 5). The system retains a history of the last 5 passwords and prevents reuse, ensuring users create unique passwords at each rotation cycle.
- Account Lockout After 5 Failed Attempts. User accounts are automatically locked after 5 consecutive failed login attempts, protecting against brute-force attacks and unauthorised access attempts.
- Password Expiry Every 60 Days. Passwords expire every 60 days, requiring users to create new credentials at regular intervals to limit the window of exposure from compromised credentials.
- Multi-Factor Authentication. After entering username and password, a one-time password (OTP) is required for every authentication event, including password resets. This ensures a strong second factor is enforced at all times, significantly reducing the risk of account compromise from stolen credentials.
- Concurrent Login Control. Simultaneous login sessions from multiple devices or locations are disallowed. This prevents session hijacking and ensures accountability for all authenticated actions within the platform.
3. Data Protection and Encryption
Amber News implements robust encryption and data protection measures to safeguard sensitive information throughout its lifecycle, from collection through storage and transmission.
- Encryption Policy. Establishes standards for encryption of data in transit and at rest, including approved algorithms, key management procedures, and certificate lifecycle management.
- TLS 1.2 Encryption for Data in Transit. All data transmitted between clients, services, and third-party integrations is encrypted using TLS 1.2 or higher, ensuring confidentiality and integrity of data in transit.
- AWS Instance Encryption (Encryption at Rest). All AWS instances and storage volumes are encrypted at rest. This includes Amazon S3 buckets storing call recordings, EBS volumes, and database storage, using AWS-managed or customer-managed encryption keys.
- Sensitive Information Encrypted in Transit and at Rest. All sensitive and personal data, including voice data, call recordings, transcripts, and account information, is encrypted both during transmission and when stored, in accordance with industry best practices.
- Secrets Rotation at Amber-Defined Frequencies. API keys, database credentials, encryption keys, and other secrets are rotated at frequencies defined by Amber News's security standards, minimising the impact of credential compromise.
- Data Classification and Handling Policy. Defines data classification levels (e.g., public, internal, confidential, restricted) and prescribes handling, storage, transmission, and disposal requirements for each classification level.
- Data Backup Policy. Defines backup schedules, retention periods, storage locations, and restoration procedures for critical data and systems. Backup integrity is tested at regular intervals.
4. Infrastructure and Network Security
Amber News deploys layered infrastructure and network security controls to protect cloud environments, network boundaries, and physical facilities against internal and external threats.
- Network Security Policy. Defines network segmentation, firewall rules, intrusion detection and prevention, and monitoring requirements. Governs both internal network architecture and external-facing services.
- Cloud Security Policy. Governs the secure configuration, deployment, and management of cloud services (AWS). Covers identity and access management, logging, encryption, and compliance controls specific to cloud infrastructure.
- CIS Controls Implementation. Infrastructure is hardened and monitored in alignment with Center for Internet Security (CIS) Controls, providing a prioritised framework of security best practices for defence against common cyber threats.
- Cloudflare Web Application Firewall (WAF). Cloudflare WAF is deployed to protect web-facing services against OWASP Top 10 vulnerabilities, DDoS attacks, bot traffic, and other application-layer threats with real-time threat detection and mitigation.
- Physical and Environmental Policy. Establishes physical access controls, environmental safeguards, and facility security requirements for offices and any physical infrastructure, including visitor management and equipment disposal.
5. Application Security and Software Development Lifecycle
Amber News integrates security into every stage of the software development lifecycle and enforces rigorous application security testing to identify and remediate vulnerabilities before they reach production.
- Software Development Lifecycle Management Policy. Formal SDLC policy governing secure development practices, code review requirements, testing standards, and deployment procedures across the entire software development lifecycle.
- Development Lifecycle Established. Structured development lifecycle with defined stages including requirements, design, development, testing, deployment, and maintenance. Security checkpoints are integrated at each stage.
- Regular Internal Vulnerability Assessments (SAST and DAST). Regular internal vulnerability assessments are conducted using both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate security weaknesses in code and running applications.
- Third-Party Penetration Testing. Independent third-party penetration testing is conducted regularly to identify vulnerabilities that internal assessments may miss, providing an objective evaluation of the security posture.
- Change Management Policy. Formal policy governing how changes to information systems, infrastructure, and applications are requested, assessed, approved, implemented, and reviewed to minimise service disruptions and security risks.
- Change Management Procedures Enforced. All changes to production systems and code follow formal change management procedures including impact assessment, approval workflows, testing, rollback plans, and post-deployment validation.
- Vulnerability Management Policy. Defines processes for identifying, classifying, prioritising, remediating, and tracking vulnerabilities across all systems, applications, and infrastructure components.
6. Monitoring, Logging and Incident Response
Amber News maintains comprehensive monitoring, logging, and incident response capabilities to detect, respond to, and recover from security incidents in a timely and effective manner.
- Logging and Monitoring Policy. Comprehensive logging and monitoring policy defining what events are logged, log retention periods, monitoring alert thresholds, and responsibilities for log review and incident escalation.
- Incident Monitoring. Continuous monitoring of systems, networks, and applications for security incidents, anomalous behaviour, and potential threats. Alerts are triaged and escalated according to defined severity levels.
- Information Incident Management Policy. Defines the incident response lifecycle including detection, classification, containment, eradication, recovery, and lessons learned. Includes breach notification procedures aligned with GDPR, DPDPA, and Jamaica DPA timelines.
7. Human Resources and Endpoint Security
Amber News ensures that security responsibilities are embedded throughout the employee lifecycle and that endpoint devices are protected with enterprise-grade security solutions.
- Human Resource Security Policy. Governs security responsibilities throughout the employee lifecycle including pre-employment screening, onboarding security training, ongoing responsibilities, and offboarding procedures including access revocation.
- Background Verification (BGV) Checks. Background verification checks are conducted for all employees prior to employment, verifying identity, employment history, criminal records, and qualifications as permitted by applicable law.
- Security Awareness Training. Security awareness training is conducted at defined intervals for all employees, covering phishing, social engineering, data handling, incident reporting, and role-specific security responsibilities.
- Endpoint Detection and Response (EDR). EDR solutions are deployed on all end-user machines, providing real-time threat detection, automated response, and forensic investigation capabilities for endpoint security incidents.
- Mobile Device Management (MDM). MDM is implemented across the organisation to enforce security policies on mobile and endpoint devices, including remote wipe capability, encryption enforcement, and application management.
- Remote Working Policy. Defines security requirements for remote and hybrid work arrangements, including secure connectivity (VPN), approved device usage, data handling, and physical workspace security.
- Asset Management Policy. Governs the identification, classification, tracking, and secure disposal of information assets, including hardware, software, and data assets throughout their lifecycle.
8. Business Continuity and Risk Management
Amber News maintains business continuity and risk management programmes to ensure service resilience and the ability to recover from disruptions, while proactively identifying and mitigating information security risks.
- Business Continuity Management Policy. Establishes the framework for business continuity planning, including business impact analysis, recovery time objectives, and continuity strategies to ensure service availability during disruptions.
- Continuity and Disaster Recovery Plans Established. Documented continuity and disaster recovery plans are in place, tested regularly, and maintained to ensure rapid recovery of critical systems and data in the event of a disaster or major incident.
- Risk Management Policy. Defines the methodology for identifying, assessing, treating, and monitoring information security risks. Includes risk appetite, risk registers, and escalation criteria for risk acceptance decisions.
- Risk Assessments Performed. Regular risk assessments are conducted to identify and evaluate threats and vulnerabilities to information assets, with results feeding into treatment plans and continuous improvement of the security programme.
9. Vendor and Third-Party Management
Amber News maintains rigorous vendor management controls to ensure that third-party service providers meet our security and data protection standards.
- Vendor Management Policy. Governs the assessment, selection, onboarding, and ongoing monitoring of third-party vendors and service providers. Includes security due diligence, contractual security requirements, and periodic vendor reviews.
- Third-Party Agreements Established. All third-party service providers are bound by Data Processing Agreements requiring data security measures, breach notification, and deletion upon termination. A current list of our sub-processors is maintained at ambernews.ai/subprocessors.
10. Payment Security
Amber News maintains PCI DSS Level 1 compliance for all payment processing activities through its partnership with Amber Pay and the PowerTranz payment gateway (a Mastercard subsidiary).
- PCI DSS Level 1 Compliance. Amber Pay, our payment processor, holds PCI DSS Level 1 certification, the highest level of payment card industry compliance. PowerTranz, the underlying payment gateway, is a Mastercard subsidiary and independently PCI DSS Level 1 certified.
- Card Data Tokenisation. All cardholder data is tokenised at the point of capture. Raw card numbers, CVVs, and magnetic stripe data are never stored on Amber News or Amber Pay systems. Tokenised references are used for all subsequent transaction processing and record-keeping.
- Payment Data Encryption. All payment data in transit is encrypted using TLS 1.2 or higher. End-to-end encryption is maintained from the point of card data entry through to the payment gateway and card network.
- Transaction Record Retention. Transaction records are retained for the period required by applicable financial regulations and card scheme rules (typically up to 7 years). Records are purged upon account closure and expiry of regulatory retention obligations.
11. Contact Us
For any questions regarding this Document or our security controls, please contact our Data Protection Officer or Security Team at:
Email (General / DPO): [email protected]
This Document is reviewed and updated periodically to reflect changes in our security posture, regulatory obligations, and threat landscape. Continued use of the Services following any update to this Document constitutes acceptance of the revised controls, to the extent permitted by applicable law.