Security

Enterprise-grade security built into every layer

SOC 2 Type II, ISO 27001, PCI DSS, GDPR, HIPAA-ready. Every transaction encrypted, every access audited, every integration secure.

Trusted by 5,000+ enterprises across the globe

Compliance & Certifications

Certifications your security team can rely on

Xoxoday's security posture is independently validated across globally recognized frameworks. Our certifications cover data security, cloud infrastructure, privacy, and compliance.

ISO/IEC 27001:2022

Certified ISMS

Xoxoday is certified to the latest ISO/IEC 27001:2022 standard, affirming a comprehensive information security management system across people, processes, and technology. Controls are independently audited and continuously improved.

SOC 2 Type II

Operating effectiveness

SOC 2 Type II report affirms our high standards in managing customer data across five trust service principles - security, availability, confidentiality, processing integrity, and privacy - validated by an independent auditor annually.

PCI DSS

Cardholder data

Xoxoday aligns with the Payment Card Industry Data Security Standard for payment processing and financial instrument handling across our rewards and incentives platform, so your financial data is always protected.

GDPR

EU data protection

GDPR compliance is built on Accountability, Privacy by Design and Default, Data Minimization, and Subject Access Rights. We operate as both data controller and processor and guarantee the same privacy standards to all customers regardless of location.

CCPA & CPRA

California privacy

Xoxoday complies with both CCPA and CPRA, protecting the privacy of sensitive personal information (SPI) and personal information (PI) for California residents, with deliberate data privacy management and enhanced opt-out rights.

HIPAA-Ready

Healthcare compliance

Xoxoday's architecture and controls are ready for BAA execution for healthcare and insurance programs. We employ robust safeguards while handling any medical information, providing organizations the confidence they need in our platform.

Security Architecture

Defense in depth across every layer

Xoxoday's security is built in layers. Every domain from identity to infrastructure has independent controls so a single failure never becomes a breach.

Identity & Access Security

Multi-layered authentication and granular access control across every module.

Authentication & MFA

MFA, session timeout, IP allowlisting, device fingerprinting, and email OTP 2FA with configurable expiry and attempt limits.

Single Sign-On (SSO)

SAML 2.0, OAuth 2.0, and OpenID Connect. LDAP authentication also supported.

Provisioning & Directory Sync

SCIM provisioning, JIT user creation, and directory sync. Password policy enforces 24h reset-link expiry, last-4 reuse block, and lockout after failed attempts.

Role-Based Access Control (RBAC)

Granular View / Edit / Create permissions across modules with custom role creation and a multi-tier Delegation-of-Authority hierarchy for separation of duties.

Operational Security

Security operations and response

Continuous monitoring. Rapid response. Guaranteed recovery. Backed by SLAs and independent audits.

P1–P4

Severity tiers with runbooks

Active

Incident Response

Documented runbooks for every severity level with automated stakeholder notification and post-incident review.

  • Severity-based escalation tiers (P1–P4)
  • Automated alerting to on-call teams
  • Post-incident review within 48 hours
  • Root cause published to status page

Quarterly

Independent penetration tests

Scheduled

Vulnerability Management

Proactive identification and remediation of security vulnerabilities across code, infrastructure, and dependencies.

  • Quarterly pentests by independent firms
  • Active bug bounty program
  • Automated dependency scanning in CI/CD
  • CVE patching within 72h for critical

< 1h RPO

Recovery point objective

Geo-redundant

Business Continuity

Geo-redundant infrastructure with automated failover, regular disaster recovery drills, and guaranteed recovery targets.

  • RPO < 1 hour, RTO < 4 hours
  • Multi-region with automatic failover
  • Bi-annual disaster recovery drills
  • Encrypted backups with 90-day retention
FAQ

Frequently asked security and compliance questions

Xoxoday maintains SOC 2 Type II, ISO 27001, PCI DSS alignment, GDPR, CCPA/CPRA compliance, HIPAA-readiness, and ISO 14001. Certifications are audited annually by independent third parties and reports are available under NDA.