Snapshot 21561
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Jun 01, 2026 Bonusly is an engaging recognition and rewards platform that enriches your company culture. Product details Product name Bonusly Product description Software-as-a-Service (SaaS) platform for employee recognition, rewards, engagement, and performance enablement. Product URL https://bonusly.com Compliance CCPA GDPR SOC2 Company details Is the company traded publicly? No Company name Bonusly Are there any material claims against the company? No Describe the role or team responsible for information security at the company The security committee is responsible for information security. The committee currently consists of: * CTO * Head of Engineering * Head of People Operations * Senior CloudOps Engineer * Senior Talent Partner When was the company founded? 2013-09-19 Company URL bonus.ly What exchange is the company listed on? n/a Subprocessors Algolia Activity: SaaS Search Functionality Data/Processing Location: USA Registered Address: 301 Howard St, 3rd floor, San Francisco, CA 94105 (USA) Amazon Web Services (AWS) Activity: Platform / Infrastructure as a service Data/Processing Location: USA Registered Address: 440 Terry Ave N, Seattle, WA 98109
 Chargebee, Inc. Activity: Subscription/billing automation Data/Processing Location: USA Registered Address: 340 S. Lemon Avenue, San Francisco Hubspot, Inc. Activity: Marketing / sales automation Data/Processing Location: USA Registered Address: 1 Harbour Pl, Suite 175. Portsmouth, NH 03801
 DataDog Activity: Application and Infrastructure monitoring Data/Processing Location: USA Registered Address: 620 8th Ave 45th Floor New York, NY 10018 USA Intercom, Inc. Activity: Customer messaging Data/Processing Location: USA Registered Address: Stephen Court, 18-21 Saint Stephen's Green, Dublin 2, Dublin Mongo DB, Inc. Activity: Hosted database services Data/Processing Location: USA Registered Address: 229 W. 43rd Street, 5th Floor, New York, NY 10036 Gainsight Activity: Customer management and support services Data/Processing Location: USA Registered Address: 655 Montgomery St., San Francisco, CA, USA Stripe, Inc./Stripe Payments Europe, Ltd. Activity: Payment processing services Data/Processing Location: USA Registered Address: 354 Oyster Point Blvd, South San Francisco, CA 94080, United States Snowflake Activity: Data warehousing Data/Processing Location: USA Registered Address: Suite 3A, 106 East Babcock Street, Bozeman, Montana 59715, USA Google Workspace Activity: Employee / office productivity software Data/Processing Location: USA Registered Address: 1600 Amphitheater Parkway, Mountain View, CA 94043, USA OpenAI Activity: Generative AI Data/Processing Location: USA Registered Address: 3180 18th Street, San Francisco, California, USA Downloadable Reports Smartly Inc. dba Bonusly SOC 2 Type 2 Report 3.31.26 Smartly Inc. dba Bonusly SOC 3 Report 3.31.26 Bonusly API and MCP Penetration Test March 2026 Bonusly Web App Penetration Test March 2026 FAQs Where is data stored? Data is stored and processed in The United States using AWS, in the US-East region. We make extensive use of the capabilities and services provided by AWS to increase privacy and control network access throughout our system. Documents that provide more details about AWS security are available at https://aws.amazon.com/whitepapers Does Bonusly ever sell customer data? We never sell data or information to any third-party vendors. Can data be deleted after a period of time? Data can be deleted at any time upon request. What employee data do you have access to? Required: First name, last name, work email. Optional but recommended: department, office location, role, and manager. Optional and only needed if using work anniversary recognition: hire date. Optional and only needed if using birthday recognition: month and day of birth. Optional and only needed if using custom swag stores: Address, city, state, postal code, country. Data is not tied to the user profile but the redeemed rewards. What does Bonusly do with our data? We enable employee recognition, rewards, and engagement. We use aggregated and de-identified data to monitor application performance and make improvements. Is data encrypted in transit and at rest? Yes to both. All Bonusly web traffic is served over HTTPS. We force HTTPS for all web resources, including our REST API, web app, and public website. We also use HSTS to ensure that browsers communicate with our services using HTTPS exclusively. Additionally, we use only strong cipher suites and only support TLS 1.2 and 1.3. Our primary databases, including backups, are fully encrypted at rest. In addition, all archives and logs are fully encrypted at rest. We use industry-standard encryption algorithms with a minimum strength of AES-256. How do your HRIS integrations work? Bonusly is able to integrate with any HRIS that can support report delivery via a flat-file transfer or API. On a high level, the HRIS will make a report available to Bonusly via flat-file transfer to an SFTP server or via API we can programmatically access. The user management integration will access this report once per night and apply any changes to the user information within Bonusly. What are the availability agreements of your application? 99.9% uptime. Track application status at https://status.bonus.ly/ Does Bonusly perform vulnerability assessments or penetration tests? Yes. Bonusly uses security tools to scan for vulnerabilities continuously. Additionally, vulnerabilities in third-party libraries and tools are monitored and software is patched or updated promptly when new issues are reported. Bonusly regularly undergoes third-party security audits and penetration testing to identify potential vulnerabilities and ensure they are addressed. Does Bonusly require security training for employees? Yes. Bonusly has mandatory, continuous security training programs for all Bonusly employees. Additionally, all employees and contractors have signed confidentiality agreements with Bonusly. Does Bonusly use firewalls? Yes. Our servers are protected by firewalls and not directly exposed to the Internet. What about logs? We aggregate logs to secure encrypted storage. All sensitive information (including passwords, API keys, and security questions) is filtered from our server logs. Log data is fully expunged after one year. Passwords We never store passwords in a form that can be retrieved. Instead, we store an irreversible cryptographic hash using a function specifically designed for this purpose. Authentication sessions are invalidated when users change key information and sessions automatically expire after a period of inactivity. Single Sign On (SSO) Bonusly is enabled for several secure single sign-on (SSO) standards, including SAML, OpenID, and OAuth. Monitoring We monitor and rate-limit authentication attempts on all accounts. Our system automatically blocklists any IP addresses responsible for suspicious authentication activity. User Roles We provide multiple user roles with different permissions levels within the product. Roles vary from account admins to users. In critical systems, we practice the principle of least privilege. Fallout, Disaster Recovery, Incident Response Bonusly is built with fault tolerance capability. Each of our services is fully redundant with replication and failover. Services are distributed across multiple AWS availability zones. These zones are hosted in physically separate data centers, protecting services against single data center failures. We maintain an incident response plan that includes procedures to be followed in the event of an unauthorized disclosure of data or other security incident. Disclosure To report a security issue email us at [email protected] and we will investigate. We request that you do not publicly disclose any issues discovered until we have addressed it. Legal Privacy Policy Terms Of Service