↑↓ navigate open Esc close
Documentation

Infrastructure and Data Location

Formal confirmation of data center in Brazil (AWS São Paulo, sa-east-1), provider certifications, file storage, and encryption in transit.

This document formally confirms where the data of the Torneyo platform (torneyo.com and app.torneyo.com) is processed and stored, and which physical and logical security guarantees apply to the infrastructure. It can be attached to proposals, contracts, and public procurement processes together with the Service Level Agreement, Privacy and Data Protection (LGPD), the Technical Specification, and the Backup and Data Recovery policy.

Data center confirmation: Brazil

Torneyo’s application and database run on Amazon Web Services (AWS) infrastructure, region sa-east-1 — São Paulo, Brazil. This means that:

  • personal and operational data (records, competitions, results, billing, audit trail) reside in Brazilian territory;
  • application processing takes place in the same region, with no international transit of database data;
  • the primary jurisdiction over stored data is Brazilian, meeting data sovereignty requirements common in public procurement.

Infrastructure components

ComponentProviderLocationContent
Application (API and management system)Amazon Web ServicesBrazil — São Paulo (sa-east-1)Processing of all platform data
Database (managed PostgreSQL — Amazon RDS)Amazon Web ServicesBrazil — São Paulo (sa-east-1)Personal and operational data
Files (photos, documents, match sheets)Cloudflare R2Global network with contractual jurisdictionBinary objects; references kept in the database in Brazil
Public website and help centerVercelGlobal network (CDN)Public content only, no data-subject data
Transactional emailsResendUnited StatesEmail notification delivery
PaymentsStripeProcessor’s own environment (PCI-DSS)Card data never passes through the platform

The complete list of subprocessors, with purposes and legal bases, is maintained in the privacy policy.

Infrastructure provider certifications

AWS, the provider of the application and database infrastructure, maintains internationally recognized certifications and independent audit reports, including ISO/IEC 27001, SOC 1, SOC 2 and SOC 3, and PCI DSS, in addition to physical security controls at its data centers. These certifications belong to the infrastructure provider and can be verified directly at aws.amazon.com/compliance. Torneyo runs on this certified infrastructure and applies, at the application layer, the technical measures described in the privacy policy.

Encryption in transit

All traffic between users and the platform — website, management app, API, and file downloads — uses TLS encryption (HTTPS), without exception. Internal communications between the application and third-party services (payments, email, storage) also occur over encrypted channels.

Availability and monitoring

Infrastructure availability is monitored by an independent external service, with a public, auditable history on the status page. Availability commitments, severity levels, and response times are formalized in the Service Level Agreement; protection against data loss is formalized in the Backup and Data Recovery policy.

Revision history

VersionDateChanges
2026.08.192026-08-19Initial version of the document.

Updated on

Keep reading