1. Independent Assessment and Partnerships
- CASA Tier 2. Amber completes the Cloud Application Security Assessment (CASA) Tier 2, the independent security assessment Google requires for applications that access restricted Google user data, and keeps it current.
- Microsoft. Amber is a certified Microsoft partner.
2. Hosting and Infrastructure
Customer data is hosted in the United States on Google Cloud and Amazon Web Services and on the other infrastructure providers listed on our Sub-processors page. These providers are responsible for the physical and environmental security of their data centers.
3. Encryption
Customer data is encrypted in transit using TLS and encrypted at rest.
4. Access Control
Access to production systems and customer data is limited to authorized personnel who need it for their role. Access uses individual accounts with multi-factor authentication and is removed promptly when no longer needed.
5. Logging and Monitoring
Access to production systems is logged, and our systems are monitored for security events.
6. Secure Development
Code changes are reviewed before deployment. We keep dependencies and infrastructure up to date with security patches.
7. Data Separation
Each customer's data is logically separated from other customers' data. When a partner works with more than one brand in Amber, each brand can see only the information shared with that brand.
8. Backups and Resilience
Customer data is backed up regularly, and backups are protected with the same level of security as production data.
9. Vendors and Sub-processors
We assess vendors for security before engaging them and bind them to written data protection terms. The vendors that process customer data are listed at amber.ai/legal/subprocessors, and we notify customers at least 30 days before adding a new one.
10. AI and Your Data
- Amber's AI features use models from the providers listed on our Sub-processors page, under commercial terms that do not permit them to train their models on customer data.
- Amber does not use customer data to train AI models that are made available to other customers.
- Data from connected email accounts is never used to create aggregated or benchmark data.
11. Email and Workspace Integrations
When a user connects a Google or Microsoft account, Amber accesses it only to provide the features the user enables, such as surfacing purchase order and supplier information from email. Amber's use of data from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Users can disconnect an account in Amber or revoke access in their Google or Microsoft account settings at any time.
12. Controls in the Product
- Role-based access. Brands control which users and partners can see and do what in their workspace.
- Approval workflows. Brands decide which actions require approval and who can approve them.
- Digital Workers under your settings. Digital Workers act only within the permissions and review settings a brand configures, and outgoing actions follow those settings.
- A record of the work. Product records link source documents, changes, and decisions, so teams can see the context behind each update.
- Sign-in options. Users can sign in with Google or Microsoft.
13. Personnel
Everyone with access to customer data is bound by confidentiality obligations and receives security training.
14. Incident Response
We maintain a process for identifying and responding to security incidents. If we confirm a security incident affecting customer personal data, we notify affected customers without undue delay, and in any event within 72 hours, as described in our Data Processing Addendum.
15. Data Retention and Deletion
Customers can export their data at any time. After a subscription ends, data remains available for export for 30 days and is then deleted within 90 days, except for routine backups, which are deleted on their normal cycle, and data we are legally required to keep.
16. Security Reviews
We are happy to support customer security reviews. Customers can request our responses to a security questionnaire once per year, as described in our Data Processing Addendum. Contact security@amber.ai.
17. Report a Vulnerability
If you believe you have found a security vulnerability in Amber, please email security@amber.ai with enough detail for us to reproduce it. Please give us reasonable time to fix the issue before disclosing it, and do not access or modify data that does not belong to you, disrupt our services, or perform testing beyond what is needed to demonstrate the issue. We will acknowledge your report and keep you updated on our progress.