Trust Center
This page is the public record of how Loyalty Methods secures ReactorCX, its enterprise loyalty platform: which attestations and certifications it holds, which controls apply, how availability is engineered, how sub-processors are governed, and how to obtain the audit reports. Nothing here requires a login. Documents that must stay under NDA are delivered through the Security Pack.
What is attested
Each item lists what an auditor verified. Auditor names, report periods and certificate numbers will be published here once confirmed.
| Item | Scope | Cadence | Evidence | Status |
|---|---|---|---|---|
| SOC 2 Type II | The ReactorCX platform and the operations that support it. Criteria: Security, Availability and Confidentiality. The auditor and the report period are stated on the report itself and are published here with it. | Annual independent audit | Report under NDA via Security Pack | SOC 2 Type II |
| ISO/IEC 27001:2022 | Information security management system for ReactorCX | Annual surveillance, three-year recertification | Certificate via Security Pack | ISO/IEC 27001:2022 |
| Penetration testing | Application and infrastructure | Annual, independent | Summary letter via Security Pack |
Loyalty Methods does not claim GDPR, CCPA, PIPEDA or PIPL "certification"; no such general scheme exists. ReactorCX supports programs subject to these regulations through its privacy modes and controls.
Controls in place
| Domain | Controls |
|---|---|
| Data protection | Encryption in transit (TLS) and at rest (AES-256); cloud-native key management; data classification and retention policies. |
| Identity and access | Multi-factor authentication; single sign-on via OpenID Connect; role-based and attribute-based access control down to folders and individual rules; least privilege for employees and vendors. |
| Network | Deny-by-default virtual private cloud with firewalls; continuous monitoring and threat detection. |
| Change management | Stage-to-production deployment; versioned configuration with JSON import and export; publish and unpublish controls; audit trail on every change. |
| Logging and audit | Access, system activity, configuration change, and member and transaction activity logged; per-activity execution log with rules fired and data used. |
| Incident response | Documented incident response plan; 24/7 operational support. |
| Business continuity | Disaster recovery and business continuity plans tested regularly; automated daily backups with recovery testing. |
| Vendor management | Third-party security reviews; confidentiality agreements for all staff and contractors. |
| Privacy | Two privacy modes: PII inside the platform with data-subject-rights support, or tokenized identifiers with PII in a client-controlled system. |
How availability is engineered
ReactorCX runs on AWS across multiple availability zones and regions. Containerized microservices scale with traffic and replace failed instances transparently. A replicated NoSQL data layer and an Apache Kafka event backbone carry production volume. Upgrades roll forward one service at a time with service-level rollback, and configuration publishes without a platform restart, so upgrades do not consume maintenance windows.
The downtime record carries its definition and as-of date. Detail on Enterprise Reliability and Scale.
How this is measured
No unplanned production outage of the ReactorCX platform since it became the primary system of record (first SafeSwitch cutover, 7-Eleven, February 2020). As of 2026-Q3.
How this is measured
Platform-wide API response-time service level. As of 2026-Q3.
Sub-processor policy
Loyalty Methods uses a small number of infrastructure and operational sub-processors, principally the cloud provider. The current list, with location and purpose, is included in the Security Pack. Changes to the list are notified to customers in advance under the terms of the contract, and customers may raise objections through their account team.
Reporting a vulnerability
Security researchers and customers can report suspected vulnerabilities to the security team through the contact page. Reports are acknowledged, triaged and tracked to resolution, and reporters are kept informed.
Frequently asked questions
How do I obtain the ReactorCX SOC 2 Type II report?
Request the Security Pack. The report is delivered under NDA by the security team, together with the ISO/IEC 27001 certificate and completed questionnaire answers.
Where is ReactorCX hosted?
On AWS, cloud-native, across multiple availability zones and regions. Regional deployment supports data residency where required.
Does Loyalty Methods use sub-processors?
Yes. The current sub-processor list is included in the Security Pack and changes are notified to customers under the contract.
Get the documents your security review needs.
SOC 2 Type II report, ISO/IEC 27001 certificate, questionnaire answers, penetration test summary and sub-processor list, under NDA, within three business days.