Activity shown in the product preview: Workflow triggered, Task complete, 12 reactions, Credits redeemed.
Run it where your regulator needs it to run
Run Loyalife in our cloud or fully on-prem, so member data stays exactly where your compliance team needs it - with no-data-loss DR, hard tenant isolation, and white-label that rebrands partner apps without a new release.
Your regulator's three non-negotiables
Before a single feature matters, an enterprise security and compliance review needs to know three things. The architecture answers all three.
Where the PII physically lives
Data-residency rules decide where member identity can sit. You choose the deployment model, and PII stays inside the perimeter your regulator approves.
Answered by deployment choice and per-tenant keys you hold.
Provable resilience
Uptime and recovery are not claims, they are evidence. Active-Active DR with real-time sync and nightly backups gives a security review something it can verify.
Answered by Active-Active DR plus retained nightly backups.
Hard tenant isolation
Co-brand partners cannot leak into each other. One instance runs many programs, each isolated across data, branding, members, config, and templates.
Answered by multi-tenant isolation with parent-level oversight.
However you answer them, you decide where your data lives.
You decide where your data lives
The same platform, two ways to run it. Pick one to see exactly where member data sits and what stays inside your perimeter.
Loyalife runs as managed SaaS in the region you choose. Each deployment is a segmented private VPC with Active-Active DR and multi-tenant isolation - your data stays resident in-region.
What runs, and where
Active-Active DR within your region
Where your member PII lives
Stays resident in the cloud region you select - it never leaves that region.
Only the front door is exposed
Members reach a hardened edge and nothing else - your data sits on private, isolated networks. Click a zone to see how each layer stays sealed off.
Clients reach the edge only -> private app -> isolated data · file transfer stays separate
Data
Isolated · encrypted
Member ledger and balances live in an isolated subnet, encrypted at rest and replicated for resilience.
Active-Active disaster recovery
Real-time asynchronous log shipping keeps a DR site in continuous sync. Simulate a primary outage to watch the DR site take over without data loss.
Primary data centre
production · on-prem
DR site
disaster recovery
Both sites are live. Asynchronous log shipping keeps the DR database continuously in syncwith the primary, so a failover doesn't lose committed data.
Nightly full backup
On top of real-time sync, a scheduled full backup is written to data-centre NAS or private-cloud storage, with a configurable retention window and fast restore.
One instance, many isolated programs - PII protected by default
Make it yours - without an engineering project
Branding, UI, credentials, and domain are configuration, not a rebuild. Click through what your team controls.

Every program, its own brand
Configure logo, colours, theme, and copy per program. Co-brand partners each get a distinct branded experience from the same instance, fully isolated.
- Logo, colour, theme and copy per program
- Isolated from other programs
- No shared branding or data
Build vs configure
Traditional white-label build vs Loyalife
How teams transform their programmes with the platform.
- Fork or rebuild the app for each partner brand
- Ship a new app-store release for every visual change
- Hand-wire credentials and isolation per tenant
- Stand up separate infra to keep partner data apart
- Engineering owns every branding and config change
Weeks of engineering per partner
Timeline
- Configure branding per program - no fork
- Push UI changes as config via server-driven UI
- Auto-generated Client ID + Secret per program
- Multi-tenant isolation built in across five dimensions
- Ops configures programs without an engineering cycle
Configure and launch, not rebuild
Timeline