Loyalty Methods’ ReactorCX Enterprise Loyalty Platform Achieves ISO/IEC 27001:2022 Certification
ReactorCX’s information security management system is now ISO/IEC 27001:2022 certified. Here is what that answers, and what it doesn’t.
Loyalty Methods has achieved ISO/IEC 27001:2022 certification for the information security management system supporting the design, development, operation, and support of ReactorCX, its enterprise loyalty platform. The certification (certificate no. US26071501) was issued by LMS Assessments Limited under accreditation from the United Accreditation Foundation, effective 15 July 2026 and valid through 14 July 2027.
It joins an assurance program already in place — annual SOC 2 Type II examinations, a publicly available SOC 3 report, and annual third-party penetration testing. The certificate and SOC 3 report are available now through the Loyalty Methods Trust Center at trustcenter.loyaltymethods.com.
ReactorCX powers enterprise loyalty programs across retail, fuel and convenience, hospitality and gaming, and financial services, processing more than 3 billion transactions a year across programs serving more than 350 million active members.
Enterprise security reviews do not ask whether a vendor holds a certification. They ask what the certification covers, who verified it, and what else stands behind it. A single stamp answers one question. The review asks three.
What does the ISO/IEC 27001:2022 certification cover?
The certification covers the information security management system supporting the design, development, operation, and support of the ReactorCX SaaS platform. It was issued by LMS Assessments Limited under accreditation from the United Accreditation Foundation, and carries certificate number US26071501.
ISO/IEC 27001:2022 defines requirements for establishing, implementing, maintaining, and continually improving an information security management system. The standard takes a risk-based, organization-wide approach across people, processes, and technology, with the objective of preserving the confidentiality, integrity, and availability of information [ISO/IEC, 2022].
How is ISO/IEC 27001 different from SOC 2 Type II and penetration testing?
Certified. Examined. Tested. Each instrument in the assurance program answers a different question.
ISO/IEC 27001 certifies the system that governs security. It requires an organization to establish, operate, and continually improve an information security management system: risk assessed rather than assumed, controls selected rather than inherited, accountability assigned rather than implied. An accredited body audits the whole apparatus and certifies that it works as a system, not as a checklist.
A SOC 2 Type II examination certifies nothing. It attests, which is the point. An independent CPA firm examines whether specific controls actually operated, effectively, over a defined period, against the AICPA’s Trust Services Criteria. Not whether the policies exist. Whether they ran.
Penetration testing asks the bluntest question of the three: does the production environment hold up under direct, adversarial pressure from people paid to break it.
Governance, operation, resistance. A management system certified, controls attested, defenses tested. One instrument alone leaves two questions open. ReactorCX customers get all three, every year.
Why does independent security assurance matter for an enterprise loyalty platform?
The reason the stack matters is what a loyalty platform actually holds. ReactorCX operates at the intersection of member identity, transaction history, rewards balances, partner-funded value, and live integrations with payment, commerce, CRM, and identity systems. That is not marketing data. It is a ledger of value owed to hundreds of millions of people, connected to the systems that move money. Organizations running business-critical programs on that ledger are entitled to assurance built the same way the platform is: structured, independent, and continuous.
What does the certification mean for organizations running on ReactorCX?
“Enterprise buyers evaluate more than platform capability. They assess whether the organization behind the technology can operate with the discipline, transparency, and resilience required of a long-term partner. ISO/IEC 27001:2022 certification extends the independent assurance we provide through our SOC program and reflects our continued investment in the security foundation supporting ReactorCX. As customer loyalty ecosystems become larger and more interconnected, we will continue strengthening that foundation alongside them.”
The certification did not change the platform. ReactorCX runs cloud-native with encryption in transit and at rest, multi-factor authentication and role-based access controls, continuous monitoring, documented incident response, and tested business-continuity and disaster-recovery processes. The certification changed what an outside party can verify about the organization operating it.
Where can the ISO/IEC 27001 certificate and SOC reports be accessed?
The ISO/IEC 27001:2022 certificate (no. US26071501) and the public SOC 3 report are available through the Loyalty Methods Trust Center at trustcenter.loyaltymethods.com. Full SOC 2 Type II reports are available to customers and prospective customers under NDA. Additional detail on the platform’s security posture is available on the Trust & Compliance page.
The system it certifies is not. ISO/IEC 27001:2022 certification extends an assurance program — annual SOC 2 Type II examinations, a public SOC 3 report, and annual third-party penetration testing — that has been in place and operating continuously.
Learn more about ReactorCX and our commitment to security: Contact Us.
Frequently asked questions
- Is ReactorCX ISO 27001 certified?
- Yes. As of July 2026, the information security management system supporting the design, development, operation, and support of ReactorCX, the enterprise loyalty platform from Loyalty Methods, is certified to ISO/IEC 27001:2022 (certificate no. US26071501).
- Who issued the ISO/IEC 27001:2022 certification?
- The certification was issued by LMS Assessments Limited under accreditation from the United Accreditation Foundation (UAF) on 15 July 2026. It is valid through 14 July 2027.
- What does the certification cover?
- It covers the information security management system supporting the design, development, operation, and support of the ReactorCX SaaS platform, spanning the people, processes, and technology involved in delivering the platform.
- What is an information security management system?
- An information security management system, or ISMS, is a structured system of governance, risk assessment, controls, and continuous improvement for managing information security across an organization. ISO/IEC 27001 defines the requirements an ISMS must meet, with the objective of preserving the confidentiality, integrity, and availability of information.
- Is ReactorCX SOC 2 compliant?
- Yes. Loyalty Methods undergoes annual SOC 2 Type II examinations of the controls supporting ReactorCX, conducted by an independent CPA firm against the AICPA’s Trust Services Criteria. A public SOC 3 report is also published for general use.
- What is the difference between ISO 27001 and SOC 2?
- ISO/IEC 27001 is a certification of the management system that governs security, issued by an accredited certification body. SOC 2 Type II is an attestation by an independent CPA firm that specific controls operated effectively over a defined period. The two are complementary: one verifies the system of governance, the other verifies that controls actually ran.
- Does Loyalty Methods perform penetration testing?
- Yes. Independent firms test the ReactorCX production environment annually, complementing the ISO/IEC 27001 certification and SOC 2 Type II examinations with direct adversarial testing.
- How do I request the full SOC 2 Type II report?
- Full SOC 2 Type II reports are available to customers and prospective customers under a non-disclosure agreement; reach out through the Contact Us page to request access. The ISO/IEC 27001:2022 certificate (no. US26071501) is available through the Loyalty Methods Trust Center at trustcenter.loyaltymethods.com, along with the public SOC 3 report.
- Why does ISO 27001 certification matter for an enterprise loyalty platform?
- Enterprise loyalty platforms hold member identity, transaction history, and rewards value, and integrate with payment, commerce, CRM, and identity systems. Independent certification of the security management system gives organizations verifiable assurance that this data is governed through a structured, audited program rather than internal claims alone.
ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, International Organization for Standardization. AICPA Trust Services Criteria for SOC 2 Type II examinations. Certification issued by LMS Assessments Limited under accreditation from the United Accreditation Foundation (certificate no. US26071501, issued 15 July 2026, valid through 14 July 2027). Loyalty Methods Trust Center, trustcenter.loyaltymethods.com.
See the Certification and Compliance Reports
The ISO/IEC 27001:2022 certificate and public SOC 3 report for ReactorCX are available now through the Loyalty Methods Trust Center.
Visit Trust Center