
An ISO/IEC27001:2013 and ISO 27018:2019 certified cloud solution
© 2026 Perx Technologies. All rights reserved.
// new script 07 sept "
IN BRIEF
A loyalty platform with strong security and privacy controls has an independently certified information security management system, protects personal data in the cloud, encrypts data in transit and at rest, minimizes what it stores, and lets your team inspect and audit every change and every reward trigger.
For banks and insurers, the practical test is whether the vendor can pass your security review quickly and whether the platform’s behaviour can be explained to a risk committee.
Perx is an ISO/IEC 27001 and ISO 27018 certified cloud solution, and its rules-based engine ran 13.4 million rule triggers in the Jenius deployment (Bank BTPN, part of SMBC Indonesia).
A loyalty platform holds behavioural and transactional data tied to real customers, so it should be assessed like any other system that touches customer data. Seven practices separate a platform a bank can approve from one it cannot.
ISO 27001 and ISO 27018 are complementary, not substitutes for each other, and holding one does not guarantee the other. ISO 27001 shows a vendor manages security as an organisation-wide discipline: risk assessment, access control, incident response. ISO 27018 goes further and shows the vendor has specifically addressed personally identifiable information sitting in a public cloud environment, which is exactly what a loyalty platform holds on your customers. A vendor with only the first certification has demonstrated general security discipline, not this specific commitment to customer data in the cloud.
A claim of certification is not the same as the certificate. Before treating a vendor’s certification as satisfying a security review, a buyer should ask for:
This is exactly why, in the comparison below, Comarch’s ISO certificates are listed as entity- and data-centre-specific. A buyer evaluating Comarch, or any vendor, for a loyalty deployment needs to confirm the certificate they have been shown covers the actual service they would run, not a different subsidiary or location.
That last question matters more in banking than in most sectors. In the Jenius deployment, Perx’s rules-based engine ran 13.4 million rule triggers, and each one came from a defined rule that a bank team could review. That is the kind of explainability a risk committee can sign off on.
The cost of maintaining certifications sits with the vendor, and it shows up in the price of the platform. The cost that a buyer controls is the cost of getting a platform approved. A vendor with current certificates, a clear scope statement and a documented answer to each item in a security questionnaire gives a bank’s security team less to chase, and a lighter review is cheaper for both sides.
The cheaper-looking option can cost more. A platform that cannot show certification, or cannot show that it covers your data residency needs, tends to surface those gaps late in procurement, when changing course is expensive. The sensible comparison is total cost to approve and run, not licence price alone.
The table below sets out what three vendors state publicly about certification and data protection. Every entry comes from the vendor’s own public pages. Buyers should confirm each claim, and its scope, directly with the vendor during due diligence.
| Platform | Security certifications stated publicly | Data protection practices stated publicly |
|---|---|---|
| Perx | ISO/IEC 27001 and ISO 27018 certified cloud solution (stated on perxtech.com) | One example of the underlying controls: a maker-checker workflow for governed changes. The certifications themselves cover a broader control set, including access management, encryption, and incident response, not this one feature alone. |
| Antavo | ISO 27001 (certified January 2022), and adherence to ISO 27017 and ISO 27018 (antavo.com security page) | TLS 1.2 or higher in transit, encrypted volumes at rest, defined data retention policies, GDPR and UK GDPR compliance, least-data principle (antavo.com security and data management pages) |
| Comarch | ISO/IEC 27001 certificates published for specific Comarch entities and data centres (comarch.com quality page); scope is entity-specific, so confirm it covers the loyalty service you would buy | Security protocols, regular penetration testing, multi-factor authentication, GDPR compliance and anonymization processes (comarch.com loyalty management page) |
Sources: perxtech.com; antavo.com/technology-integrations/security and antavo.com data management and compliance page; comarch.com/company/quality and comarch.com loyalty management page. Vendor pages change, so re-check before relying on any entry.
Perx is also working on the next phase of the platform, which is focused on additional deployment options for banks with strict data residency requirements.

Praveen Vadla is Senior Digital Marketing Manager at Perx Technologies. With over 10 years of experience in B2B SaaS marketing across the US and Southeast Asia, he focuses on customer loyalty, engagement, and retention strategy. He writes on how brands build lasting customer relationships in a mobile-first economy. Connect with Praveen on LinkedIn.

Blogs

Blogs

Sustainability

Blogs

Blogs
Perx Technologies Pte Ltd
20A Tanjong Pagar Road
Singapore 088443
An ISO/IEC27001:2013 and ISO 27018:2019 compliant cloud solution


© 2026 Perx Technologies. All rights reserved.
© 2026 Perx Technologies. All rights reserved.
© 2026 Perx Technologies. All rights reserved.
Hey! Shashank