Security you can verify, not just read about
ReactorCX, the enterprise loyalty platform from Loyalty Methods, holds a SOC 2 Type II attestation and ISO/IEC 27001:2022 certification, encrypts data in transit and at rest, enforces role-based and attribute-based access control, supports single sign-on via OpenID Connect, and runs in one of two privacy modes: PII inside the platform, or tokenized identifiers with PII held in your systems.
SOC 2 Type II
Annual independent audit

ISO/IEC 27001:2022
Information security management
Penetration testing
Independent, annual
Privacy regimes
GDPR, CCPA, PIPEDA, PIPL ready
Controls by trust service category
Independent auditors verify these controls each year. The categories in scope are stated on the Trust Center with the report period.
Security
- Encryption in transit (TLS) and at rest (AES-256), cloud-native key management
- Multi-factor authentication and role-based access control
- Continuous monitoring and threat detection
- Deny-by-default virtual private cloud with firewalls
- Documented incident response procedures
- Regular penetration testing and vulnerability assessment
Confidentiality
- Encrypted storage and transmission of sensitive data
- Least-privilege access for employees and vendors
- Confidentiality agreements for all staff and contractors
- Data classification and retention policies
- Third-party vendor security reviews
Availability
- High-availability infrastructure across zones and regions
- Disaster recovery and business continuity plans, tested regularly
- Automated daily backups with recovery testing
- Performance monitoring and proactive scaling
- 24/7 operational support and incident response
Controls inside the platform
| Control | What it does |
|---|---|
| Single sign-on (OIDC) | Enterprise users authenticate through the identity provider their organization already operates rather than maintaining separate ReactorCX credentials. |
| Role-based and attribute-based access | Per-user and per-role permissions across configuration, servicing and reporting; attribute-based access extends to folders and individual rules, so teams, brands and regions are governed separately inside one deployment. |
| Audit logs | Access, system activity, configuration changes and member and transaction activity are logged, supporting compliance reviews, dispute resolution and regulatory inquiries. |
| Stage-to-production change control | Changes are built in a stage environment, versioned, exported as JSON, reviewed and published without a restart; publish and unpublish control when rules are active. |
| Two privacy modes | PII inside the platform with full data-subject-rights support (access, deletion, rectification, restriction of processing, portability), or tokenized identifiers with PII held in a client-controlled system. |
| Regional deployment | Multi-region deployment supports data residency where required. |
MGM Resorts operates ReactorCX with membership numbers only; no PII is stored in the loyalty platform.
Who is asking
OIDC single sign-on, with roles and attribute constraints by brand, banner and owner.
What they may see
Access is scoped to the data that role owns; personal data can stay out of the platform entirely.
What is recorded
Access, configuration change and transaction are each written to an audit trail.
What you can evidence
SOC 2 Type II and ISO/IEC 27001:2022, with security questionnaires answered from evidence.
Built for programs subject to GDPR, CCPA, PIPEDA and PIPL
There is no general certification scheme for these regulations, so ReactorCX does not claim one. What it provides is the machinery a regulated program needs: a choice of privacy mode, data-subject-rights tooling, regional deployment, and audit trails that show what happened to a record and why. Your privacy office sets the policy; ReactorCX supplies the controls and the evidence.
What the Security Pack contains
- Current SOC 2 Type II report (under NDA)
- ISO/IEC 27001:2022 certificate and statement of applicability summary
- Completed security questionnaire answers (SIG or CAIQ format)
- Penetration test summary letter
- Sub-processor list and data-flow overview
Frequently asked questions
Is ReactorCX SOC 2 compliant?
ReactorCX holds a SOC 2 Type II attestation with annual audit (SOC 2 Type II attestation). The trust service criteria in scope, the auditor and the report period are published on the Trust Center.
Does ReactorCX support enterprise single sign-on?
Yes. ReactorCX supports single sign-on via OpenID Connect, working alongside role-based and attribute-based access controls.
How does ReactorCX handle PII?
Two privacy modes: PII stored inside the platform with full data-subject-rights support, or tokenized identifiers with PII held in a client-controlled system.
Does ReactorCX hold a GDPR certification?
There is no GDPR certification scheme in general use. ReactorCX is designed to support programs subject to GDPR, CCPA, PIPEDA and PIPL through its privacy modes, data-subject-rights tooling and regional deployment options.
How do I get the SOC 2 report?
Request the Security Pack. It includes the current SOC 2 Type II report, the ISO/IEC 27001 certificate and completed security questionnaire answers, delivered under NDA.
Send your questionnaire. We answer it in full.
The Security Pack is delivered by the security team within three business days of a signed NDA.