Enterprise Security

Security & Trust Center

What we run, where it runs, who else touches your data, and how long any of it survives. For what we collect and the rights you have over it, see our Privacy Policy.

Hosting & Storage

All data is hosted and processed in the United States — Amazon Web Services us-east-1 (N. Virginia), on DynamoDB and S3. Storage is encrypted at rest, and everything in transit is served over TLS. Buckets holding capture artifacts are private, with no public access.

Identity & Authentication

Authentication is handled by AWS Cognito, which supports both a one-time passcode sent to your email and a conventional password. Where a password is used, Cognito holds the credential — it is never stored by our application, and our servers never see it in plain text. One-time codes are valid for 10 minutes and are rate limited on both sending and verification.

Data Retention & Deletion

Retention is enforced by storage lifecycle rules rather than by manual cleanup, so it happens whether or not anyone is watching. Capture artifacts expire at 90 days and agent logs at 30. Full table below.

Access Control & Secrets

Production access is limited to staff who need it for operations or support. Application credentials and API keys are held in a managed secrets store and injected at runtime, never committed to source control. Tenant data is scoped per account on every read path.

Data Processing Agreement

We offer a standard DPA for enterprise plans, covering confidentiality, security obligations and the subprocessor list below. A2Z Reach operates from the United States and all processing happens there, so no cross-border transfer mechanism is invoked. Contact us to execute one.

Incident Response

If a breach affects your personal data we will notify affected customers without undue delay, and any regulator that US federal or state law requires us to notify, with what we know, what we are doing, and what you should do.

Data Retention

Computed metrics and dashboards are derived from captures and outlive them — deleting a raw artifact at 90 days does not remove the historical trend built from it. Closing your account removes both.

DataRetention
AI engine capture artifacts90 days, then deleted automatically
Fleet capture artifacts90 days, then deleted automatically
Agent execution logs30 days, then deleted automatically
Account and brand configurationLife of account, deleted within 30 days of closure

Authorized Subprocessors

A2Z Reach engages the following subprocessors to deliver the platform. Each is bound by contract to process data only on our instructions.

SubprocessorPurposeData Location
Amazon Web Services, Inc.Cloud hosting, DynamoDB and S3 storage, Cognito authenticationUnited States (us-east-1)
OpenAI, LLCSemantic categorisation and topic analysis of brand promptsUnited States
Stripe, Inc.Subscription billing and payment processing (PCI DSS Level 1)United States
DataForSEO LLCSearch keyword, ranking and demand data for SEO featuresEuropean Union / United States
Cal.com, Inc.Scheduling for demo and enterprise calls booked from our websiteUnited States

AI engines queried on your behalf

The platform submits your configured prompts to ChatGPT, Claude, Gemini, Google AI Overviews, Perplexity and records the responses. These engines receive prompts — brand and topic queries — and handle them under their own terms rather than ours. Because a prompt is effectively a public search query, it should never contain personal or confidential information.

Vulnerability Disclosure & Compliance

If you have found a security vulnerability, report it to security@a2zreach.ai. Please give us enough detail to reproduce it, and time to fix it before disclosing publicly. We do not pursue legal action against researchers who report in good faith and do not access or destroy other customers' data.

For compliance documentation or to execute a DPA, contact the same address.