Security & Trust Center
What we run, where it runs, who else touches your data, and how long any of it survives. For what we collect and the rights you have over it, see our Privacy Policy.
Hosting & Storage
All data is hosted and processed in the United States — Amazon Web Services us-east-1 (N. Virginia), on DynamoDB and S3. Storage is encrypted at rest, and everything in transit is served over TLS. Buckets holding capture artifacts are private, with no public access.
Identity & Authentication
Authentication is handled by AWS Cognito, which supports both a one-time passcode sent to your email and a conventional password. Where a password is used, Cognito holds the credential — it is never stored by our application, and our servers never see it in plain text. One-time codes are valid for 10 minutes and are rate limited on both sending and verification.
Data Retention & Deletion
Retention is enforced by storage lifecycle rules rather than by manual cleanup, so it happens whether or not anyone is watching. Capture artifacts expire at 90 days and agent logs at 30. Full table below.
Access Control & Secrets
Production access is limited to staff who need it for operations or support. Application credentials and API keys are held in a managed secrets store and injected at runtime, never committed to source control. Tenant data is scoped per account on every read path.
Data Processing Agreement
We offer a standard DPA for enterprise plans, covering confidentiality, security obligations and the subprocessor list below. A2Z Reach operates from the United States and all processing happens there, so no cross-border transfer mechanism is invoked. Contact us to execute one.
Incident Response
If a breach affects your personal data we will notify affected customers without undue delay, and any regulator that US federal or state law requires us to notify, with what we know, what we are doing, and what you should do.
Data Retention
Computed metrics and dashboards are derived from captures and outlive them — deleting a raw artifact at 90 days does not remove the historical trend built from it. Closing your account removes both.
| Data | Retention |
|---|---|
| AI engine capture artifacts | 90 days, then deleted automatically |
| Fleet capture artifacts | 90 days, then deleted automatically |
| Agent execution logs | 30 days, then deleted automatically |
| Account and brand configuration | Life of account, deleted within 30 days of closure |
Authorized Subprocessors
A2Z Reach engages the following subprocessors to deliver the platform. Each is bound by contract to process data only on our instructions.
| Subprocessor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, DynamoDB and S3 storage, Cognito authentication | United States (us-east-1) |
| OpenAI, LLC | Semantic categorisation and topic analysis of brand prompts | United States |
| Stripe, Inc. | Subscription billing and payment processing (PCI DSS Level 1) | United States |
| DataForSEO LLC | Search keyword, ranking and demand data for SEO features | European Union / United States |
| Cal.com, Inc. | Scheduling for demo and enterprise calls booked from our website | United States |
AI engines queried on your behalf
The platform submits your configured prompts to ChatGPT, Claude, Gemini, Google AI Overviews, Perplexity and records the responses. These engines receive prompts — brand and topic queries — and handle them under their own terms rather than ours. Because a prompt is effectively a public search query, it should never contain personal or confidential information.
Vulnerability Disclosure & Compliance
If you have found a security vulnerability, report it to security@a2zreach.ai. Please give us enough detail to reproduce it, and time to fix it before disclosing publicly. We do not pursue legal action against researchers who report in good faith and do not access or destroy other customers' data.
For compliance documentation or to execute a DPA, contact the same address.