Third Party Index

Snapshot 27200

Document
Security page
URL
https://www.xoxoday.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
135129 bytes
SHA-256 (raw)
3a18fa2e137ecb9048e490dc595193bcabe4919fc94f95dda700181ed82e91b8
SHA-256 (normalized text)
2ee4368ff114d1a5f0c04ac6b864411174902094deb1084aebccfe423c23d525

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
Enterprise-grade security built into every layer
SOC 2 Type II, ISO 27001, PCI DSS, GDPR, HIPAA-ready. Every transaction encrypted, every access audited, every integration secure.
View trust center
Trusted by 5,000+ enterprises across the globe
Compliance & Certifications
Certifications your security team can rely on
Xoxoday's security posture is independently validated across globally recognized frameworks. Our certifications cover data security, cloud infrastructure, privacy, and compliance.
ISO/IEC 27001:2022
Certified ISMS
Xoxoday is certified to the latest ISO/IEC 27001:2022 standard, affirming a comprehensive information security management system across people, processes, and technology. Controls are independently audited and continuously improved.
SOC 2 Type II
Operating effectiveness
SOC 2 Type II report affirms our high standards in managing customer data across five trust service principles - security, availability, confidentiality, processing integrity, and privacy - validated by an independent auditor annually.
PCI DSS
Cardholder data
Xoxoday aligns with the Payment Card Industry Data Security Standard for payment processing and financial instrument handling across our rewards and incentives platform, so your financial data is always protected.
GDPR
EU data protection
GDPR compliance is built on Accountability, Privacy by Design and Default, Data Minimization, and Subject Access Rights. We operate as both data controller and processor and guarantee the same privacy standards to all customers regardless of location.
CCPA & CPRA
California privacy
Xoxoday complies with both CCPA and CPRA, protecting the privacy of sensitive personal information (SPI) and personal information (PI) for California residents, with deliberate data privacy management and enhanced opt-out rights.
HIPAA-Ready
Healthcare compliance
Xoxoday's architecture and controls are ready for BAA execution for healthcare and insurance programs. We employ robust safeguards while handling any medical information, providing organizations the confidence they need in our platform.
Security Architecture
Defense in depth across every layer
Xoxoday's security is built in layers. Every domain from identity to infrastructure has independent controls so a single failure never becomes a breach.
Identity & Access Security
Multi-layered authentication and granular access control across every module.
Authentication & MFA
MFA, session timeout, IP allowlisting, device fingerprinting, and email OTP 2FA with configurable expiry and attempt limits.
Single Sign-On (SSO)
SAML 2.0, OAuth 2.0, and OpenID Connect. LDAP authentication also supported.
Provisioning & Directory Sync
SCIM provisioning, JIT user creation, and directory sync. Password policy enforces 24h reset-link expiry, last-4 reuse block, and lockout after failed attempts.
Role-Based Access Control (RBAC)
Granular View / Edit / Create permissions across modules with custom role creation and a multi-tier Delegation-of-Authority hierarchy for separation of duties.
Operational Security
Security operations and response
Continuous monitoring. Rapid response. Guaranteed recovery. Backed by SLAs and independent audits.
P1–P4
Severity tiers with runbooks
Active
Incident Response
Documented runbooks for every severity level with automated stakeholder notification and post-incident review.
Severity-based escalation tiers (P1–P4)
Automated alerting to on-call teams
Post-incident review within 48 hours
Root cause published to status page
Quarterly
Independent penetration tests
Scheduled
Vulnerability Management
Proactive identification and remediation of security vulnerabilities across code, infrastructure, and dependencies.
Quarterly pentests by independent firms
Active bug bounty program
Automated dependency scanning in CI/CD
CVE patching within 72h for critical
< 1h RPO
Recovery point objective
Geo-redundant
Business Continuity
Geo-redundant infrastructure with automated failover, regular disaster recovery drills, and guaranteed recovery targets.
RPO < 1 hour, RTO < 4 hours
Multi-region with automatic failover
Bi-annual disaster recovery drills
Encrypted backups with 90-day retention
FAQ
Frequently asked security and compliance questions
Xoxoday maintains SOC 2 Type II, ISO 27001, PCI DSS alignment, GDPR, CCPA/CPRA compliance, HIPAA-readiness, and ISO 14001. Certifications are audited annually by independent third parties and reports are available under NDA.