AICPA SOC 2 Type II compliance logo for the ReactorCX platform by Loyalty Methods

ReactorCX completes its SOC 2® Audit! Security is our Top Priority.

SOC 2 Type II
Compliance Report

Security, availability, and confidentiality - independently audited to meet enterprise data protection standards.

SOC 2 Certified
Certified Loyalty Methods
SOC 2 Type II
Security Availability Confidentiality
View full report
Implementation · Loyalty Platform Migration

SafeSwitch™: Zero-Downtime Enterprise Loyalty Platform Migration

ReactorCX runs in parallel with the platform you have today, validates against your full member base and production traffic, and switches members over only after it already produces the same answers. No member-visible downtime, no reconstructed balances, no going dark.

SafeSwitch™ · Migration Command Center
Live
Legacy Platform Live
Serving Members Authoritative
ReactorCX Shadow Mode
Mirrored Traffic Matching Results
Production Event Stream
Parallel Processing
Live Reconciliation
Live Reconciliation
Matching…
Every balance and tier checked against production
Shadow Run
Reconcile
Cutover
Reversal Ready

Trusted by

7-Eleven logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
MGM Resorts logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
Gap logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
Western Union logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
Speedway logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
BP logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
TravelCenters of America logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
Stripes logo, enterprise loyalty client migrated to ReactorCX via SafeSwitch
Overview

SafeSwitch™ is the cutover methodology Loyalty Methods uses to move enterprise loyalty programs onto the ReactorCX platform without member-visible downtime or lost data. Rather than a single big-bang switch, SafeSwitch™ runs ReactorCX in parallel with the legacy system and advances through a four-gate validation sequence, reconciling every balance, tier, and transaction against the live program before any member is moved. A documented rollback path stays available until the switch is confirmed correct in production. Across 700M+ members migrated and 6B+ records reconciled, every SafeSwitch™ cutover has landed with zero member-visible downtime.

700M+
Members Migrated
6B+
Records Reconciled
100%
Zero-Downtime Cutovers
How does SafeSwitch™ make a high-risk migration a non-event?

Most platforms prove correctness in production, after the point of no return. SafeSwitch™ proves it first, against your full member base and production traffic, before a single member moves. These are the gates and capabilities that define a SafeSwitch™ cutover. The methodology runs deeper than any single page can hold. Proven in production across 7-Eleven, MGM Resorts, Gap Inc., and Western Union.

The Risk

Why is replacing a legacy loyalty platform so risky?

A loyalty program is a ledger of accumulated trust. Members can see their points, their status, and their history, and they notice the instant any of it is wrong. The traditional approach treats migration as a single event: freeze the old system, move the data, open the new one, and hope. A big-bang cutover gives you one attempt and no way back.

The error is also asymmetric. Members forgive a slow page and forget a brief outage. They do not forgive a points balance that fell overnight, a tier they earned and no longer hold, or a reward that vanished. Rip-and-replace does not fail because the data is hard to copy. It fails because correctness is hard to prove, and the traditional approach proves it in production, with real members, after the point of no return.

What a big-bang cutover finds out too late
  • A rule configured differently in production than the documented terms, found after members do.
  • A balance off across a tier, found at the call center.
  • A platform that cannot hold day-one load, found when every location transacts at once.
  • Live earning rules, redemption logic, and every integration, all tested at once on the first day real members are present.
The Cutover Sequence

How does the SafeSwitch™ four-gate cutover work?

SafeSwitch™ replaces the single event with a sequence. ReactorCX advances through four gates, and traffic does not move until each one is cleared. A rollback path stays live the entire time, until the final switch is confirmed.

1
Gate 1
Shadow Run

ReactorCX is stood up alongside the legacy system, configured with the program's full rule set, and connected to the same production event stream the legacy platform receives. Every qualifying transaction that hits the old system also flows to the new one. Nothing is simulated. The new platform processes real production traffic from day one, in shadow, with no member exposure.

2
Gate 2
Reconcile

With both systems processing identical traffic, their outputs are compared. Every balance, every tier state, every earned and redeemed point is reconciled against the legacy platform across the entire member base, not a sample. Where the two systems disagree, the discrepancy is run down to its cause. The gate clears only when the new platform produces the same answers as the old one, account by account, and keeps matching as new transactions arrive.

3
Gate 3
Cutover

Only now does live traffic move to ReactorCX. Because the platform has already been validated against the full member base and the full production load, the switch is a redirect, not a rebuild. Members never see it. The legacy system stays available the entire time.

4
Gate 4
Reversal Ready

The legacy system stays running, current, and synchronized, and the rollback path stays armed until ReactorCX is confirmed correct in live production. If anything does not match what reconciliation predicted, traffic returns to the legacy platform without a restore and without data loss, because the old system never stopped being correct. The rollback is not a recovery plan. It is a system that is still on.

Gate Capabilities

What capabilities make each gate trustworthy?

The four gates are the spine. The capabilities that run inside them are what make each gate trustworthy.

Zero member-visible downtime

The switch happens after the parallel run, not instead of it. By the time traffic moves, ReactorCX has been processing production volume in shadow for the full validation. The cutover changes which system answers; it does not pause the program to find out whether the new system can.

Built-in program rule audit

Documented terms and live behavior drift apart over years of operation. SafeSwitch™ replays real transactions through both the rules as documented and the rules as they actually run, then shows where the two diverge, so you know what your program is really doing before you carry it forward.

Replay and reprocessing

When reconciliation finds a difference, affected transactions are replayed through corrected logic and balances are reprocessed at scale. A rule fixed once is applied everywhere it should have applied, with no back office rebuilding balances by hand. This is how 6B+ records are reconciled.

Built-in performance testing

Replay moves faster than live traffic, so a year of volume can be processed in a fraction of the time. For a program running 3B+ transactions a year, that proves the platform carries well beyond peak, against the program's own production history, the real mix of transaction types and seasonal peaks, not a synthetic load model.

Real production preview

Every member-facing output the new platform will generate is reviewed from real data before a single member sees it: statements, balances, tier progression, and the surfaces in the Member Care Portal. Stakeholders sign off on what members will actually experience, not on a specification of it.

Risk moves to before go-live

In a traditional cutover, the riskiest moment is the first hour with real members, because that is when correctness is finally tested. SafeSwitch™ moves that test forward. Every check that normally happens in production, with members watching, happens during reconciliation, with no one exposed.

The Full Migration

How do SafeSwitch™ and ThreadSync™ work together?

ThreadSync™ and SafeSwitch™ are two phases of the same migration. ThreadSync™ is the implementation methodology that builds and validates the program: instead of running the work in sequence, it runs six workstreams in parallel from kickoff, which is how a program that would otherwise take eighteen months reaches go-live in nine. SafeSwitch™ is the cutover methodology that follows, the four gates that move members onto the validated platform without disruption.

ThreadSync™ builds and proves the program. SafeSwitch™ proves the switch. Together they take an enterprise loyalty program from kickoff through go-live with zero member-facing disruption and no data loss.

Migration Framework · Phase 02 & 03
ThreadSync™ · Phase 02 Parallel Build & Validate
Workstream 1
Workstream 2
Workstream 3
Workstream 4
Workstream 5
Workstream 6
Validated Platform
SafeSwitch™ · Phase 03 Controlled Cutover
Gate 1 · Shadow Run
Gate 2 · Reconcile
Gate 3 · Cutover
Gate 4 · Reversal Ready
Zero-Downtime Go-Live
Production Proof

What is the SafeSwitch™ migration track record?

The record is the same across every ReactorCX legacy replacement: zero member-visible downtime. Not a target. The outcome. Across all engagements, Loyalty Methods has migrated 700M+ members and reconciled 6B+ records with zero seconds of downtime.

MGM Resorts: 75M accounts migrated, 3 systems unified across the MGM Rewards portfolio.

Western Union: 220M+ members across 35+ countries, the largest single migration on record.

Gap Inc. Encore: 100M+ members across 4 brands and 3,000+ storefronts, zero member-visible disruption at cutover in February 2026.

7-Eleven: 13,000+ stores across the US and Canada, zero downtime, live since 2018.

BP Earnify: 5 brands unified under one program with 50+ integrated partners.

There was a time when you could close the stores for a few hours and run a migration overnight. That world is gone. Members shop on their phones all the time, so zero downtime is not the goal, it is the baseline. With SafeSwitch™ we reconciled hundreds of millions of historical transactions and brought four brands onto one platform, and members did not feel a thing.

Emil Sarkissian, CEO, Loyalty Methods. From the Gap Inc. session at CRMC 2026.
Enterprise Security

Is SafeSwitch™ built to clear enterprise IT and procurement?

A parallel run means member data lives in two systems during the migration window, which raises the bar on how it is protected, not lowers it. Every cutover runs within the SOC 2 Type II certified ReactorCX platform, under the same controls that govern the program in steady-state operation.

SOC 2 Type II GDPR
01
Role-based and attribute-based access control

Controlled provisioning, with access scoped, constrained, and logged.

02
Encryption

In transit (TLS) and at rest (AES-256), with cloud-native key management.

03
SSO via standard federation

Integrates with your existing identity provider.

04
Full audit trails

Access, configuration-change, and transaction activity logging across the migration.

05
Two privacy modes

PII inside the platform with full data subject rights, or tokenized identifiers with PII held in a client-controlled system.

06
AWS cloud-native

Horizontally scalable, multi-environment, disaster-recovery patterns.

FAQ

Frequently Asked Questions

Everything you need to know about how SafeSwitch™ moves an enterprise loyalty program onto ReactorCX without downtime or data loss.

Platform What is SafeSwitch™, and how does Loyalty Methods use it for enterprise loyalty platform migrations?

SafeSwitch™ is the proprietary cutover methodology developed by Loyalty Methods that enables zero-downtime transitions from legacy loyalty systems to the ReactorCX platform. SafeSwitch™ treats cutover as a procedural sequence, not an event: four sequential gates prove the new platform is ready before traffic moves, and a rollback path stays on standby if validation fails. Across 700 million+ members migrated and 6 billion+ records reconciled, every SafeSwitch™ cutover has landed without member-visible downtime. SafeSwitch™ is Phase 03 in the Loyalty Methods migration framework, preceded by Vision Alignment (Phase 01) and ThreadSync™ (Phase 02). All customers to date where ReactorCX replaced a legacy system have used SafeSwitch™ for the cutover.

The SafeSwitch™ cutover sequence consists of four gates that execute in order, each with a defined pass/fail criterion. Gate 1, Shadow Run: full production traffic mirrored against ReactorCX while the legacy system continues to serve members. Gate 2, Reconcile: every record verified against the legacy system's output, with the gate held until all records match. Gate 3, Cutover: production traffic moves to ReactorCX in a defined window with named owners, and members never see the switch. Gate 4, Reversal Ready: documented rollback path maintained until post-switch stability is confirmed. No gate advances unless the prior gate passes. This procedural discipline is what has produced a 100% success rate with zero seconds of downtime across all SafeSwitch™ migrations.

The shadow run is Gate 1 of the SafeSwitch™ cutover sequence. During the shadow run, ReactorCX processes all production traffic in parallel with the legacy system. Every transaction, balance update, tier calculation, and reward issuance that the legacy system handles is simultaneously processed by ReactorCX, without exposing members to ReactorCX until the client team is comfortable with the results. The shadow run provides a real production preview: the client team sees exactly what ReactorCX would do with all of their production traffic before any switch happens. This is not a simulation against sample data. It is full production traffic, mirrored.

Reconciliation is Gate 2 of the SafeSwitch™ cutover sequence. After the shadow run, every record processed by ReactorCX is verified against the legacy system's output. The reconciliation gate blocks the cutover unless every record matches. Any discrepancy identified during reconciliation is resolved before the process advances. This gate is what eliminates the category of post-launch data integrity issues that plague conventional loyalty platform migrations, where discrepancies between old and new systems surface only after members are already on the new platform.

The SafeSwitch™ built-in program rule audit discovers exactly what is running in the legacy system's production environment and compares it against the program's terms and conditions. Enterprise loyalty programs accumulate configuration drift over years of operation: promotional rules never removed, tier qualification logic that diverged from documented business rules, earn rates that differ from what program terms specify. The SafeSwitch™ program rule audit uncovers these discrepancies with 100% accuracy by running the full production workload through both systems and comparing outputs. This audit often surfaces issues the client team did not know existed, providing a clean baseline for the ReactorCX configuration before cutover.

Post-to-pre go-live risk transfer means that issues typically discovered after a production launch are surfaced and resolved before the cutover happens. In conventional loyalty platform migrations, the first weeks after go-live are spent identifying and fixing discrepancies while members are actively using the new platform. SafeSwitch™ inverts this pattern: because the shadow run processes full production traffic through ReactorCX before the switch, the reconciliation gate catches discrepancies before members are ever exposed to the new system. The typical post-go-live stabilization period is compressed into the pre-go-live validation phase, so the actual cutover lands as a non-event for both staff and members.

SafeSwitch™ replay allows the client team to rewind all production traffic and re-process it through ReactorCX as many times as needed to identify and fix all discrepancies. When the shadow run or reconciliation gate surfaces a mismatch, the team does not need to wait for new production traffic to test the fix. Replay re-runs the same production workload through the corrected configuration, confirming the fix against the same real-world conditions that exposed the issue. This cycle repeats until all discrepancies are resolved, with no impact on the live production environment or on members.

SafeSwitch™ replay runs 5 to 10 times faster than normal production traffic, which means the client team has production-grade proof that ReactorCX can scale to at least 10 to 15 times normal production volume, without any dedicated performance testing infrastructure or separate load-testing engagement. The performance evidence comes from real production transaction patterns, not synthetic test scripts, so it reflects actual program behavior at scale. This eliminates the conventional requirement for a separate performance testing phase and provides confidence in headroom that synthetic tests cannot replicate. At 7-Eleven, this validated sub-second response times (30 to 40% faster than legacy) with 10x scale headroom before the switch, proven on real production data, not benchmarks.

SafeSwitch™'s real production preview lets the client team see exactly what ReactorCX would do with all of their production traffic, without actually exposing members to ReactorCX until the team is comfortable with the results. The client team can evaluate earn calculations, tier qualifications, reward issuances, and member balance updates against real production conditions before making the switch decision. This preview operates against the full member base and the full transaction volume, not a subset or a sample. The difference between a preview on a 10% sample and a preview on 100% of production traffic is the difference between confidence and certainty.

Gate 4 of the SafeSwitch™ cutover sequence is Reversal Ready. A documented rollback path is maintained after cutover until post-switch stability is confirmed. The rollback path provides a defined procedure for reverting traffic to the legacy system if any issue surfaces after the switch. Across all SafeSwitch™ migrations to date, the rollback path has rarely been needed, but it remains a procedural requirement on every engagement, consistent with the same discipline that governs the other three gates. The rollback is not a contingency afterthought; it is a gate.

ThreadSync™ (Phase 02) governs how the implementation is organized and executed: six parallel workstreams run concurrently from kickoff, compressing eighteen-month programs to nine. SafeSwitch™ (Phase 03) governs the cutover: four sequential gates that prove the new platform is ready before traffic moves. ThreadSync™ builds and validates the program. SafeSwitch™ ensures the switch happens without member-facing disruption or data loss. Both phases are preceded by Vision Alignment (Phase 01), which maps requirements to architecture and delivery plan before engineering begins. Together, all three phases have produced a 100% project success record with zero seconds of downtime across 700 million+ members migrated.

SafeSwitch™ has maintained a 100% success rate with zero seconds of downtime across every migration where ReactorCX replaced a legacy system. Named enterprise migrations include MGM Resorts (75M accounts migrated, 3 systems unified across the entire MGM Rewards portfolio), Western Union (220M+ members across 35+ countries, the largest single migration on record), Gap Inc. Encore (100M+ members across 4 brands and 3,000+ storefronts, zero member-visible disruption at cutover in February 2026), 7-Eleven (13,000+ stores across the US and Canada, zero downtime, live since 2018), and BP Earnify (5 brands unified under one program with 50+ integrated partners). Across all engagements, Loyalty Methods has migrated 700 million+ members and reconciled 6 billion+ records with zero seconds of downtime.

All SafeSwitch™ migrations run within the SOC 2 Type II certified ReactorCX platform. During the shadow run, reconciliation, and cutover phases, data handling follows the same security controls that govern the production platform: encryption in transit (TLS), encryption at rest (AES-256), role-based and attribute-based access controls, SSO via standard federation protocols, and comprehensive audit logs. ReactorCX supports two privacy modes during migration: storing PII inside the platform with full data subject rights support, or operating with tokenized identifiers where PII is stored externally in a client-controlled system. The privacy model is determined during implementation and governs data handling across all four cutover gates. MGM Resorts operates with membership numbers only, with no PII stored in the loyalty platform.

Connect
Want to migrate without the risk?

Walk through your cutover with the team that has migrated 700M+ members onto ReactorCX with zero member-visible downtime.