Security & Trust Center
At A2Z Reach, we treat your brand data with enterprise-grade security. We host our infrastructure on highly compliant platforms and ensure strict access control and data retention policies.
Hosting & Storage
All data is hosted and processed securely in Amazon Web Services (AWS) in the us-east-1 (N. Virginia) region. We leverage DynamoDB and encrypted S3 buckets for raw execution storage.
Identity & Authentication
We use AWS Cognito for secure, passwordless authentication using one-time verification passcodes (OTP). No passwords are stored on our servers.
Data Retention & Deletion
Captured AI engine response documents and extraction logs are retained for exactly 90 days before automatic deletion. Account configurations are kept for the duration of the account and deleted within 30 days of closure.
Data Processing Agreement (DPA)
We offer standard Data Processing Agreements (DPA) for enterprise plans containing EU Standard Contractual Clauses (SCCs). Contact our support desk to execute a DPA for your organization.
Authorized Subprocessors
A2Z Reach engages the following subprocessors to deliver core analytics, crawler monitoring, and AI engine tracking captures:
| Subprocessor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud Hosting, Database Storage, AWS Cognito Authentication | United States (us-east-1) |
| OpenAI, LLC | Semantic categorization & topic analysis of brand prompts | United States |
Vulnerability Disclosure & Auditing
If you have discovered a security vulnerability or wish to request our compliance documentation (SOC 2 Type II readiness report), please contact our security team directly at:security@a2zreach.ai