Activity shown in the product preview: Workflow triggered, Task complete, 12 reactions, Credits redeemed.

Fraud & Security

Enterprise-grade security built into every layer

SOC 2 Type II, ISO 27001, GDPR, HIPAA-ready. Every transaction encrypted, every access audited, every reward compliant.

Trusted by security teams at 5,000+ companies

Adobe
Behr
Capgemini
Cosentino
Continental
Freshworks
H&M
HSBC
Kantar
Kennametal
Kohler
Michelin
Nielsen
Xero
Adobe
Behr
Capgemini
Cosentino
Continental
Freshworks
H&M
HSBC
Kantar
Kennametal
Kohler
Michelin
Nielsen
Xero
Adobe
Behr
Capgemini
Cosentino
Continental
Freshworks
H&M
HSBC
Kantar
Kennametal
Kohler
Michelin
Nielsen
Xero
Security Architecture

Defense in depth across every layer

Multi-layered authentication and session management.

Authentication & Session

MFA, session timeout, IP allowlisting, device fingerprinting.

Single Sign-On (SSO)

SAML 2.0, OAuth 2.0, OpenID Connect.

Supported Protocols

SCIM provisioning, JIT user creation, directory sync.

Operational Security

Security operations and response

Continuous monitoring. Rapid response. Guaranteed recovery. Backed by SLAs and independent audits.

< 24h

Incident response SLA

Active

Incident Response

Documented runbooks for every severity level with automated stakeholder notification and post-incident review.

  • Severity-based escalation tiers (P1–P4)
  • Automated PagerDuty + Slack alerting
  • Post-incident review within 48 hours
  • Root cause published to status page

Quarterly

Independent penetration tests

Scheduled

Vulnerability Management

Proactive identification and remediation of security vulnerabilities across code, infrastructure, and dependencies.

  • Quarterly pentests by independent firms
  • Active bug bounty program
  • Automated dependency scanning in CI/CD
  • CVE patching within 72h for critical

< 1h RPO

Recovery point objective

Geo-redundant

Business Continuity

Geo-redundant infrastructure with automated failover, regular disaster recovery drills, and guaranteed recovery targets.

  • RPO < 1 hour, RTO < 4 hours
  • Multi-region AWS with auto-failover
  • Bi-annual disaster recovery drills
  • Encrypted backups with 90-day retention

Data minimization

What we collect, what we don't, and how we shrink it

What we collect

Transaction events, account access logs, redemption records, and recipient identifiers needed for delivery.

What we don't store

Payment card numbers, recipient SSNs or passport numbers, bank account credentials, and any data we don't need.

How we shrink the surface

Encryption at rest, role-based access, scoped API tokens, and automatic retention windows on every record.

Compliance

Certifications and standards

SOC 2 Type II

Annual audit by an independent firm covering security, availability, and confidentiality trust service criteria.

ISO 27001

Certified information security management system covering people, processes, and technology controls.

GDPR

Full compliance with the EU General Data Protection Regulation including DPA, data portability, and right to erasure.

CCPA/CPRA

California Consumer Privacy Act and California Privacy Rights Act compliance for US data subjects.

HIPAA-Ready

Architecture and controls ready for BAA execution for healthcare and insurance reward programs.

PCI DSS

Payment Card Industry Data Security Standard alignment for payment processing and card data handling.

Deployment

Deploy where your security policy demands

Choose the model that fits your compliance requirements, data residency rules, and IT policy. All three are fully supported.

PUBLIC CLOUD · FULLY MANAGED

Public Cloud

Multi-tenant SaaS on public cloud (AWS, Azure, GCP). Fully managed by Xoxoday - infrastructure, security, patching, and uptime. SOC 2 Type II audited annually.

  • AWS-hosted, multi-region with auto-failover
  • 99.9% uptime SLA
  • Automatic security patches and updates
  • Fastest time to live - same day
DEDICATED · SINGLE-TENANT

Private Cloud

Dedicated single-tenant environment on AWS, Azure, or GCP. Your region, your data residency, fully isolated from all other customers.

  • Single-tenant - no shared compute or storage
  • Your choice of cloud region
  • Available on AWS, Azure, or GCP
  • Custom uptime and support SLAs
MAX CONTROL · YOUR INFRASTRUCTURE

On-Premise

Deployed entirely in your own data center. Your infrastructure, your security perimeter, complete data sovereignty. Xoxoday provides software and dedicated support.

  • Runs entirely inside your network
  • No data leaves your infrastructure
  • Air-gapped deployment available on request
  • Your security and compliance policies apply
Common questions

Everything you would want to know

Xoxoday maintains SOC 2 Type II, ISO 27001, GDPR, CCPA/CPRA compliance, HIPAA-readiness, and PCI DSS alignment. Certifications are audited annually by independent third parties and reports are available under NDA.