Snapshot 27200
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security Enterprise-grade security built into every layer SOC 2 Type II, ISO 27001, PCI DSS, GDPR, HIPAA-ready. Every transaction encrypted, every access audited, every integration secure. View trust center Trusted by 5,000+ enterprises across the globe Compliance & Certifications Certifications your security team can rely on Xoxoday's security posture is independently validated across globally recognized frameworks. Our certifications cover data security, cloud infrastructure, privacy, and compliance. ISO/IEC 27001:2022 Certified ISMS Xoxoday is certified to the latest ISO/IEC 27001:2022 standard, affirming a comprehensive information security management system across people, processes, and technology. Controls are independently audited and continuously improved. SOC 2 Type II Operating effectiveness SOC 2 Type II report affirms our high standards in managing customer data across five trust service principles - security, availability, confidentiality, processing integrity, and privacy - validated by an independent auditor annually. PCI DSS Cardholder data Xoxoday aligns with the Payment Card Industry Data Security Standard for payment processing and financial instrument handling across our rewards and incentives platform, so your financial data is always protected. GDPR EU data protection GDPR compliance is built on Accountability, Privacy by Design and Default, Data Minimization, and Subject Access Rights. We operate as both data controller and processor and guarantee the same privacy standards to all customers regardless of location. CCPA & CPRA California privacy Xoxoday complies with both CCPA and CPRA, protecting the privacy of sensitive personal information (SPI) and personal information (PI) for California residents, with deliberate data privacy management and enhanced opt-out rights. HIPAA-Ready Healthcare compliance Xoxoday's architecture and controls are ready for BAA execution for healthcare and insurance programs. We employ robust safeguards while handling any medical information, providing organizations the confidence they need in our platform. Security Architecture Defense in depth across every layer Xoxoday's security is built in layers. Every domain from identity to infrastructure has independent controls so a single failure never becomes a breach. Identity & Access Security Multi-layered authentication and granular access control across every module. Authentication & MFA MFA, session timeout, IP allowlisting, device fingerprinting, and email OTP 2FA with configurable expiry and attempt limits. Single Sign-On (SSO) SAML 2.0, OAuth 2.0, and OpenID Connect. LDAP authentication also supported. Provisioning & Directory Sync SCIM provisioning, JIT user creation, and directory sync. Password policy enforces 24h reset-link expiry, last-4 reuse block, and lockout after failed attempts. Role-Based Access Control (RBAC) Granular View / Edit / Create permissions across modules with custom role creation and a multi-tier Delegation-of-Authority hierarchy for separation of duties. Operational Security Security operations and response Continuous monitoring. Rapid response. Guaranteed recovery. Backed by SLAs and independent audits. P1–P4 Severity tiers with runbooks Active Incident Response Documented runbooks for every severity level with automated stakeholder notification and post-incident review. Severity-based escalation tiers (P1–P4) Automated alerting to on-call teams Post-incident review within 48 hours Root cause published to status page Quarterly Independent penetration tests Scheduled Vulnerability Management Proactive identification and remediation of security vulnerabilities across code, infrastructure, and dependencies. Quarterly pentests by independent firms Active bug bounty program Automated dependency scanning in CI/CD CVE patching within 72h for critical < 1h RPO Recovery point objective Geo-redundant Business Continuity Geo-redundant infrastructure with automated failover, regular disaster recovery drills, and guaranteed recovery targets. RPO < 1 hour, RTO < 4 hours Multi-region with automatic failover Bi-annual disaster recovery drills Encrypted backups with 90-day retention FAQ Frequently asked security and compliance questions Xoxoday maintains SOC 2 Type II, ISO 27001, PCI DSS alignment, GDPR, CCPA/CPRA compliance, HIPAA-readiness, and ISO 14001. Certifications are audited annually by independent third parties and reports are available under NDA.