Prepared for Ring certification · Last updated: 30 August 2026
ProofClock is metadata-only. The architecture below has no media pipeline: no video, image, or audio is ever requested, transferred, or stored. The only Ring data in the system is motion-event timestamps, device metadata, and the account email captured at linking.
1. Data storage locations and systems
All data is stored in AWS us-east-1 (N. Virginia), encrypted at rest with AWS-managed encryption. No customer data is stored outside AWS or on local devices.
Not stored anywhere: video, images, audio, media clips, snapshots, faces, or biometric data. Ring OAuth tokens are stored server-side in DynamoDB and never reach the browser.
2. Data flow between systems
Hop
Data transferred
Protection
Ring → Lambda (webhook)
Motion-event timestamp, device id/status, request id
TLS; HMAC-SHA256 signature verified on raw body; dedupe
Ring → Lambda (linking)
OAuth code → tokens; account id + email via Users API
TLS; 60-second code; tokens stored server-side only
Lambda ↔ DynamoDB
Metadata and derived verdicts
TLS; IAM least-privilege; encrypted at rest
Browser ↔ API
Sites, schedules, verdicts for the signed-in account
Recipient address and message content: sign-in codes, team invitations (which name the inviting owner), account service notices, and — only if the customer turns it on — a weekly summary listing that customer’s own site names and verdict counts
TLS; no video, images or audio, and no Ring device identifiers
Erbacci LLC (Wyoming, USA) · Contact: info@erbacciltd.com · ProofClock · Powered by Ring