Infrastructure and Data Location
Formal confirmation of data center in Brazil (AWS São Paulo, sa-east-1), provider certifications, file storage, and encryption in transit.
This document formally confirms where the data of the Torneyo platform (torneyo.com and app.torneyo.com) is processed and stored, and which physical and logical security guarantees apply to the infrastructure. It can be attached to proposals, contracts, and public procurement processes together with the Service Level Agreement, Privacy and Data Protection (LGPD), the Technical Specification, and the Backup and Data Recovery policy.
Data center confirmation: Brazil
Torneyo’s application and database run on Amazon Web Services (AWS) infrastructure, region sa-east-1 — São Paulo, Brazil. This means that:
- personal and operational data (records, competitions, results, billing, audit trail) reside in Brazilian territory;
- application processing takes place in the same region, with no international transit of database data;
- the primary jurisdiction over stored data is Brazilian, meeting data sovereignty requirements common in public procurement.
Infrastructure components
| Component | Provider | Location | Content |
|---|---|---|---|
| Application (API and management system) | Amazon Web Services | Brazil — São Paulo (sa-east-1) | Processing of all platform data |
| Database (managed PostgreSQL — Amazon RDS) | Amazon Web Services | Brazil — São Paulo (sa-east-1) | Personal and operational data |
| Files (photos, documents, match sheets) | Cloudflare R2 | Global network with contractual jurisdiction | Binary objects; references kept in the database in Brazil |
| Public website and help center | Vercel | Global network (CDN) | Public content only, no data-subject data |
| Transactional emails | Resend | United States | Email notification delivery |
| Payments | Stripe | Processor’s own environment (PCI-DSS) | Card data never passes through the platform |
The complete list of subprocessors, with purposes and legal bases, is maintained in the privacy policy.
Infrastructure provider certifications
AWS, the provider of the application and database infrastructure, maintains internationally recognized certifications and independent audit reports, including ISO/IEC 27001, SOC 1, SOC 2 and SOC 3, and PCI DSS, in addition to physical security controls at its data centers. These certifications belong to the infrastructure provider and can be verified directly at aws.amazon.com/compliance. Torneyo runs on this certified infrastructure and applies, at the application layer, the technical measures described in the privacy policy.
Encryption in transit
All traffic between users and the platform — website, management app, API, and file downloads — uses TLS encryption (HTTPS), without exception. Internal communications between the application and third-party services (payments, email, storage) also occur over encrypted channels.
Availability and monitoring
Infrastructure availability is monitored by an independent external service, with a public, auditable history on the status page. Availability commitments, severity levels, and response times are formalized in the Service Level Agreement; protection against data loss is formalized in the Backup and Data Recovery policy.
Revision history
| Version | Date | Changes |
|---|---|---|
| 2026.08.19 | 2026-08-19 | Initial version of the document. |