AICPA SOC 2 Type II compliance logo for the ReactorCX platform by Loyalty Methods

ReactorCX completes its SOC 2® Audit! Security is our Top Priority.

SOC 2 Type II
Compliance Report

Security, availability, and confidentiality - independently audited to meet enterprise data protection standards.

SOC 2 Certified
Certified Loyalty Methods
SOC 2 Type II
Security Availability Confidentiality
View full report

SOC 2 Compliance &

Security Assurance

Loyalty Methods is SOC 2 Type II compliant, demonstrating our commitment to the highest standards of security, confidentiality, and availability. Our independent audit verifies that ReactorCX meets rigorous trust service criteria, ensuring compliance and protection for your data.

SOC 2 Type II compliance and enterprise security assurance for the ReactorCX Loyalty Engine by Loyalty Methods, protecting enterprise loyalty data through audited security, availability, and confidentiality controls

Trusted by

7-Eleven logo, convenience retail client powered by Loyalty Methods' ReactorCX
Gap logo, apparel and fashion client powered by Loyalty Methods' ReactorCX
MGM Resorts logo, hospitality and gaming client powered by Loyalty Methods' ReactorCX
BP logo, fuel and convenience client powered by Loyalty Methods' ReactorCX
Western Union logo, financial services client powered by Loyalty Methods' ReactorCX
Athleta logo, apparel and fashion client powered by Loyalty Methods' ReactorCX
ON Running logo, apparel and fashion client powered by Loyalty Methods' ReactorCX
Banana Republic logo, apparel and fashion client powered by Loyalty Methods' ReactorCX
Speedway logo, convenience retail client powered by Loyalty Methods' ReactorCX
TravelCenters of America logo, fuel and convenience client powered by Loyalty Methods' ReactorCX
Stripes logo, convenience retail client powered by Loyalty Methods' ReactorCX
AICPA SOC 2 Type II compliance logo for the ReactorCX platform by Loyalty Methods

SOC 2 Compliance – Trust Service Criteria

AICPA SOC 2 Type II compliance logo for the ReactorCX platform by Loyalty Methods

Loyalty Methods has successfully met all compliance requirements across the following trust service categories, as verified by independent auditors. Click on each category to view how we ensure compliance.

Security trust service criterion in the ReactorCX Loyalty Engine by Loyalty Methods, covering encryption, multi-factor authentication, role-based access control, continuous monitoring, secure VPC, incident response, and annual penetration testing

Security – Protection against unauthorized access and threats

Security trust service criterion in the ReactorCX Loyalty Engine by Loyalty Methods, covering encryption, multi-factor authentication, role-based access control, continuous monitoring, secure VPC, incident response, and annual penetration testing

Ensuring the integrity and security of our systems through industry-leading security controls.

Confidentiality – Safeguarding sensitive data in accordance with contractual and regulatory requirements

Confidentiality trust service criterion in the ReactorCX Loyalty Engine by Loyalty Methods, covering encrypted storage and transmission, least-privilege access enforcement, confidentiality agreements, data classification policies, and third-party security reviews

Ensuring that sensitive customer data remains protected and is only accessible to authorized personnel.

Confidentiality trust service criterion in the ReactorCX Loyalty Engine by Loyalty Methods, covering encrypted storage and transmission, least-privilege access enforcement, confidentiality agreements, data classification policies, and third-party security reviews
Availability trust service criterion in the ReactorCX Loyalty Engine by Loyalty Methods, covering high-availability infrastructure, disaster recovery, automated daily backups, performance monitoring, automatic scaling, and 24/7 operational support

Availability – Ensuring system reliability and uptime for continuous operations

Availability trust service criterion in the ReactorCX Loyalty Engine by Loyalty Methods, covering high-availability infrastructure, disaster recovery, automated daily backups, performance monitoring, automatic scaling, and 24/7 operational support

Delivering a high-availability environment with built-in redundancies and disaster recovery.

FAQ

Frequently Asked Questions

Everything you need to know about how ReactorCX powers customized loyalty rewards and offers at enterprise scale.

ReactorCX configures rewards through a flexible rule engine that supports any combination of earn rates, redemption options, tier benefits, and personalized incentives. Rewards can be triggered by:

  • Purchases and transactional activity
  • Non-transactional activities - referrals, event attendance, social engagement
  • Partner-attributed actions

Every reward rule supports the four dimensions of eligibility - Who (member segments), Where (location), When (time), and What (activity, product, offer) - and runs in real time across mobile apps, point of sale, kiosks, and partner channels.

One rule engine governs every reward type. No parallel systems, no configuration duplication - just a single framework that handles the full complexity of enterprise loyalty.

ReactorCX delivers dynamic offers personalized to each member based on real-time event signals, segment membership, location, channel, and historical behavior. Two members can see the same campaign with completely different parameters.

Segmentation is updated on every event, keeping eligibility decisions current to the second - not to the last overnight batch run.

Offers can be tested with control groups, capped by budget, throttled by frequency, and previewed before they go live - giving program managers full control over reach, cost, and impact before any offer is published.

Static and dynamic segmentation both supported. The platform auto-generates segments, accepts CRM-defined ones, or imports from external sources - reusable across every offer and promotion.

A single transaction can trigger dozens of overlapping offers - BOGO deals, mix-and-match combos, vendor-funded promotions, and cents-per-gallon rollbacks. ReactorCX evaluates every valid combination mathematically and returns the optimal allocation in subsecond time.

Arbitration policies are configurable: customer-first, business-first, or vendor-protected. Loyalty earning and promotional discounting resolve in a single real-time call - not two separate systems stitched together after the fact.

ReactorCX supports the full discount library required by enterprise loyalty programs:

  • BOGO (buy one get one) offers
  • Mix-and-match combinations and combo pricing
  • Ticket-level and item-level discounts
  • Cents-per-gallon rollbacks at fuel forecourts
  • Percentage off, dollar off, and package pricing

The platform handles complex SKU-level promotions and exclusions, mandatory product groups, and segment-specific discount eligibility. All discount types resolve through the same arbitration engine for optimal customer outcomes.

No discount type requires a separate system or integration. Everything runs through a single engine - keeping the transaction fast, the logic consistent, and the outcome optimal.

ReactorCX segmentation is event-driven and updated in real time. Members can be segmented by:

  • Purchase behavior, RFM (recency, frequency, monetary)
  • Demographics and channel preference
  • Tier status and lifecycle stage
  • Geography or any custom attribute

Segments can be auto-generated by the platform, defined in a connected CRM, or imported from external sources. Every segment is reusable across promotions, eligibility rules, and personalization logic - powering both reward configuration and offer targeting from a single definition.

ReactorCX is API-first and event-native, with three integration modes - API, events, and batch - supporting connections to CRM platforms, retail and F&B point of sale, kiosks, mobile apps, gaming systems, hotel property management systems, marketing automation platforms, and customer service tools.

Loyalty Methods has integrated ReactorCX with 30,000+ locations across enterprise programs including Western Union, 7-Eleven, MGM Resorts, Fontainebleau, TravelCenters of America, and Stripes. The platform connects to existing tech stacks without rip-and-replace.

ReactorCX processes 2.6 billion transactions annually across retail, fuel, hospitality, and financial services on a single real-time engine, with subsecond response times across every channel.

The platform has maintained zero downtime in production since 2018 - a track record that underpins every enterprise deployment.

Enterprise scale is proven across some of the world's largest programs:

  • Complex promotions across 13,000+ stores at 7-Eleven
  • Real-time discounting at 8,500+ bp and Amoco fuel locations
  • Multi-property tier management across the full MGM Resorts portfolio

ReactorCX is SOC 2 Type II certified, with an independent audit by CertPro covering Security, Availability, Processing Integrity, Confidentiality, and Privacy controls. Loyalty Methods performs SOC 2 assessments on an annual basis.

The platform supports global data protection regulation compliance for programs handling member rewards data across multiple regions and jurisdictions - critical for enterprise programs operating across markets with varying regulatory requirements.

At Loyalty Methods, security, confidentiality, and availability are fundamental to how we operate.

Our SOC 2 compliance reflects our commitment to maintaining the highest standards of data protection and operational integrity. We continuously invest in security measures to safeguard our clients’ data and ensure the reliability of our platform.

To explore our security policies, compliance certifications, and more, visit our Trust Center.