Trust Center

Trust Center

This page is the public record of how Loyalty Methods secures ReactorCX, its enterprise loyalty platform: which attestations and certifications it holds, which controls apply, how availability is engineered, how sub-processors are governed, and how to obtain the audit reports. Nothing here requires a login. Documents that must stay under NDA are delivered through the Security Pack.

Attestations and certifications

What is attested

Each item lists what an auditor verified. Auditor names, report periods and certificate numbers will be published here once confirmed.

Attestations and certifications held by Loyalty Methods for ReactorCX
ItemScopeCadenceEvidenceStatus
SOC 2 Type IIThe ReactorCX platform and the operations that support it. Criteria: Security, Availability and Confidentiality. The auditor and the report period are stated on the report itself and are published here with it.Annual independent auditReport under NDA via Security PackSOC 2 Type II
ISO/IEC 27001:2022Information security management system for ReactorCXAnnual surveillance, three-year recertificationCertificate via Security PackISO/IEC 27001:2022
Penetration testingApplication and infrastructureAnnual, independentSummary letter via Security Pack

Loyalty Methods does not claim GDPR, CCPA, PIPEDA or PIPL "certification"; no such general scheme exists. ReactorCX supports programs subject to these regulations through its privacy modes and controls.

Controls summary

Controls in place

Control summary
DomainControls
Data protectionEncryption in transit (TLS) and at rest (AES-256); cloud-native key management; data classification and retention policies.
Identity and accessMulti-factor authentication; single sign-on via OpenID Connect; role-based and attribute-based access control down to folders and individual rules; least privilege for employees and vendors.
NetworkDeny-by-default virtual private cloud with firewalls; continuous monitoring and threat detection.
Change managementStage-to-production deployment; versioned configuration with JSON import and export; publish and unpublish controls; audit trail on every change.
Logging and auditAccess, system activity, configuration change, and member and transaction activity logged; per-activity execution log with rules fired and data used.
Incident responseDocumented incident response plan; 24/7 operational support.
Business continuityDisaster recovery and business continuity plans tested regularly; automated daily backups with recovery testing.
Vendor managementThird-party security reviews; confidentiality agreements for all staff and contractors.
PrivacyTwo privacy modes: PII inside the platform with data-subject-rights support, or tokenized identifiers with PII in a client-controlled system.
Availability model

How availability is engineered

ReactorCX runs on AWS across multiple availability zones and regions. Containerized microservices scale with traffic and replace failed instances transparently. A replicated NoSQL data layer and an Apache Kafka event backbone carry production volume. Upgrades roll forward one service at a time with service-level rollback, and configuration publishes without a platform restart, so upgrades do not consume maintenance windows.

The downtime record carries its definition and as-of date. Detail on Enterprise Reliability and Scale.

Feb 2020
Zero unplanned production downtime since
How this is measured

No unplanned production outage of the ReactorCX platform since it became the primary system of record (first SafeSwitch cutover, 7-Eleven, February 2020). As of 2026-Q3.

<200 ms
Platform API response SLA
How this is measured

Platform-wide API response-time service level. As of 2026-Q3.

Sub-processors

Sub-processor policy

Loyalty Methods uses a small number of infrastructure and operational sub-processors, principally the cloud provider. The current list, with location and purpose, is included in the Security Pack. Changes to the list are notified to customers in advance under the terms of the contract, and customers may raise objections through their account team.

Responsible disclosure

Reporting a vulnerability

Security researchers and customers can report suspected vulnerabilities to the security team through the contact page. Reports are acknowledged, triaged and tracked to resolution, and reporters are kept informed.

FAQ

Frequently asked questions

How do I obtain the ReactorCX SOC 2 Type II report?

Request the Security Pack. The report is delivered under NDA by the security team, together with the ISO/IEC 27001 certificate and completed questionnaire answers.

Where is ReactorCX hosted?

On AWS, cloud-native, across multiple availability zones and regions. Regional deployment supports data residency where required.

Does Loyalty Methods use sub-processors?

Yes. The current sub-processor list is included in the Security Pack and changes are notified to customers under the contract.

Get the documents your security review needs.

SOC 2 Type II report, ISO/IEC 27001 certificate, questionnaire answers, penetration test summary and sub-processor list, under NDA, within three business days.