Amber Pay is a digital payment platform that lets merchants and individuals accept and send payments via QR code, shareable payment links, an embeddable payment gateway, and an online storefront. It is built and operated by Amber Innovations Limited, the software development and technology arm of the Amber Group of Companies.
Because the platform stores, processes, and transmits cardholder data, it is certified as a PCI DSS Level 1 Service Provider, the most rigorous of the four PCI compliance levels. Separately, Amber Innovations holds a SOC 2 Type II attestation over the Amber Innovations Processing System, of which the Amber Pay platform is an in-scope component. Both certifications are held by Amber Innovations Limited as the operating entity.
Together these cover all five trust principles, including Security, Availability, Processing Integrity, Confidentiality, and Privacy, supported by key security controls across identity and access management, infrastructure protection, vulnerability management, monitoring and incident response, secure development, business continuity, risk management, third party governance, data protection, and encryption.
The Payment Card Industry Data Security Standard applies to every entity that stores, processes, or transmits cardholder data or sensitive authentication data. Amber Pay is certified at Level 1, the highest of the four service provider levels, against PCI DSS v4.0.1, and is reassessed annually by a qualified security assessor. Our Attestation of Compliance is published below.

SOC 2 Type II sets the requirements for effective internal controls across the Trust Principles of Security, Availability, Processing Integrity, Confidentiality, and Privacy. Amber Innovations has been independently examined against all five, with controls tested for both suitability of design and operating effectiveness across the period 1 February 2026 to 31 July 2026.
The SOC 2 examination covered the Amber Innovations Processing System, with Amber Pay named as an in-scope platform. It spans production and supporting non-production environments, the underlying cloud infrastructure, core application and service delivery components, and the systems used to store and process data for enterprise clients, along with platform operations, incident management, change management, access management, and backup and recovery. The PCI DSS assessment covers the cardholder data environment supporting the payment platform.
Systems are protected against unauthorised access, disclosure, and damage through role based access control, enforced multi-factor authentication, hardened managed devices, and continuous monitoring.
Infrastructure is designed for resilience with multi-region redundancy, uptime monitoring with automated alerting, automated backups, and a business continuity plan with defined recovery objectives.
Data is enriched, validated, and delivered without loss, delay, or corruption. Syntactic and semantic validation, manual spot checks, and reconciliation reports across webhook, API, and batch exports underpin all processing commitments.
Information designated confidential is protected with encryption at rest and in transit, need-to-know access subject to periodic review, data loss prevention, and confidentiality agreements binding every employee and contractor.
Personal data is collected, used, retained, and disposed of per our published privacy policy, the GDPR, and Jamaica's Data Protection Act, with documented procedures for access, rectification, restriction, and erasure.
Access is granted on a least-privilege basis, tied to job role and business need, with role based access control and multi-factor authentication enforced across systems and accounts. Access is provisioned on joining, reviewed on a regular cycle, and revoked promptly on departure or role change.
Employee devices are centrally managed and hardened, with endpoint detection and response, data loss prevention, mandatory full-disk encryption, removable media blocking, and web filtering. Perimeter traffic is filtered and inspected, and remote access requires an encrypted VPN with MFA.
A risk-based programme identifies, assesses, and remediates weaknesses across infrastructure and applications. Findings come from regular internal scanning and annual third-party penetration tests, and are prioritised by severity and tracked to closure.
Security events across endpoints, network devices, and cloud systems are aggregated and reviewed centrally through a SIEM platform, supported by intrusion detection and prevention and continuous uptime monitoring. Our incident response process covers triage, communication, remediation, and root cause analysis.
A documented Secure Software Development Methodology governs design, coding, testing, and deployment. Changes pass through a controlled CI/CD pipeline with peer code review, staging tests, version control, strict approval and audit mechanisms, and documented rollback procedures.
A formal business continuity and disaster recovery plan defines recovery time and recovery point objectives. Critical data is backed up automatically across redundant multi-region infrastructure with encryption enforced, alerting on failure, and regular restoration testing.
A documented risk assessment and treatment plan covers data security, regulatory obligations, vendor dependencies, and technology risks, with defined operational priorities. Senior management incorporates the results into decision-making and resourcing.
Service providers and subservice organisations are monitored through contractual arrangements, periodic reviews, and oversight activities. Independent assurance reports from our cloud provider are reviewed annually.
Data, personnel, devices, systems, and facilities are managed under a documented asset management policy, with handling and access controls applied by sensitivity. Data is retained only as long as contractual or regulatory obligations require, then securely disposed of.
Encryption standards are applied across the data lifecycle under a formal cryptography policy. Cloud storage and managed databases are encrypted, endpoints and servers use full-disk encryption, and data in transit is secured with modern TLS. Keys are managed under policy.
Sensitive card information is encrypted and handled within a defined cardholder data environment, assessed annually against PCI DSS v4.0.1 at Level 1. Access to that environment is restricted on a need-to-know basis, and the people, technologies, and processes supporting it are subject to the same access, monitoring, and change controls described above.
The in-scope system is hosted by Amazon Web Services in the United States, using multi-region deployments for high availability. AWS is responsible for physical and environmental security of the data centres hosting our production infrastructure. We review their SOC 2 Type II and ISO 27001 reports annually.
Kuya Technologies supports software design, development, testing, maintenance, and technical operations under Amber Innovations' policies, standards, and oversight. Amber Innovations retains ownership, governance, and accountability for the security and privacy of the service.
Manage your application accounts and available security settings, safeguard user IDs and passwords, review access rights periodically, and revoke access promptly for terminated or reassigned personnel.
Define acceptable data types for entry into the Amber Pay system in line with your classification and privacy requirements, transmit over secure or encrypted channels, and safeguard system-generated outputs and reports.
Notify Amber Pay promptly if you discover or suspect an incident involving our services, and act on our communications about platform changes that may affect security or availability.
Deploy endpoint protection on all devices used to access Amber Pay's services, and maintain independent business continuity and disaster recovery plans for your own environments.
Our PCI DSS Attestation of Compliance is published and available to download directly. It confirms Amber Pay's status as a Level 1 Service Provider under PCI DSS v4.0.1.
Unlike the Attestation of Compliance, the full SOC 2 Type II report is confidential. It includes the description of the Amber Innovations Processing System and the auditor's tests of controls and results, and is released on request.
To gain access to the report, please contact privacy@myambergroup.com. Include your organisation, your relationship to Amber Pay, your name and role, and the reason for the request.
Contact privacy@myambergroup.com
Use of the report is restricted to Amber Innovations, user entities of the Amber Innovations Processing System, business partners subject to risks arising from interactions with the system, prospective user entities and business partners, practitioners providing services to those parties, and regulators with sufficient knowledge of the service and the inherent limitations of internal control. Unauthorised use, reproduction, or distribution of the report, in whole or in part, is strictly prohibited.