// new script 07 sept "

Praveen Vadla

Senior Digital Marketing Manager | September 24, 2026

How to Choose a Loyalty Platform With Strong Security and Privacy Controls: A Checklist for Banks and Insurers

IN BRIEF

A loyalty platform with strong security and privacy controls has an independently certified information security management system, protects personal data in the cloud, encrypts data in transit and at rest, minimizes what it stores, and lets your team inspect and audit every change and every reward trigger.

For banks and insurers, the practical test is whether the vendor can pass your security review quickly and whether the platform’s behaviour can be explained to a risk committee.

Perx is an ISO/IEC 27001 and ISO 27018 certified cloud solution, and its rules-based engine ran 13.4 million rule triggers in the Jenius deployment (Bank BTPN, part of SMBC Indonesia).

What Are the Best Practices for Loyalty Platform Security and Privacy?

A loyalty platform holds behavioural and transactional data tied to real customers, so it should be assessed like any other system that touches customer data. Seven practices separate a platform a bank can approve from one it cannot.

  • Independent certification: an information security management system certified by an accredited body, not a self-declared policy.
  • Personal data protection in the cloud: a standard aimed specifically at personally identifiable information held in public cloud services.
  • Encryption: data encrypted in transit and at rest.
  • Access governance: role-based access and a maker-checker workflow, so no single person can change a live programme unreviewed.
  • Audit trail: a record of who changed which rule, reward or configuration, and when.
  • Data minimization and retention: store only what the programme needs, and delete it on a defined schedule or on request.
  • Incident response and testing: regular penetration testing and a documented process for handling incidents.

How Do ISO 27001 and ISO 27018 Differ for Loyalty Solutions?

ISO/IEC 27001 sets the requirements for an information security management system: how an organisation identifies risk, applies controls and keeps improving them. ISO/IEC 27018 is a code of practice for protecting personally identifiable information in public cloud services. ISO/IEC 27017 covers security controls for cloud services more broadly.

Why Buyers Should Ask for Both Certifications, and for the Certificate Itself

ISO 27001 and ISO 27018 are complementary, not substitutes for each other, and holding one does not guarantee the other. ISO 27001 shows a vendor manages security as an organisation-wide discipline: risk assessment, access control, incident response. ISO 27018 goes further and shows the vendor has specifically addressed personally identifiable information sitting in a public cloud environment, which is exactly what a loyalty platform holds on your customers. A vendor with only the first certification has demonstrated general security discipline, not this specific commitment to customer data in the cloud.

A claim of certification is not the same as the certificate. Before treating a vendor’s certification as satisfying a security review, a buyer should ask for:

  • The certificate itself, not just a badge or a line of text on a website.
    The name of the accredited certification body that issued it.
  • The edition of the standard. Standards get revised on a cycle, and a vendor still citing a retired edition may be overdue for recertification.
  • The scope statement: which legal entity, product line or data centre the certificate actually covers.
  • The issue and expiry date, since certification is only valid for a defined audit cycle, not indefinitely.

This is exactly why, in the comparison below, Comarch’s ISO certificates are listed as entity- and data-centre-specific. A buyer evaluating Comarch, or any vendor, for a loyalty deployment needs to confirm the certificate they have been shown covers the actual service they would run, not a different subsidiary or location.

How Do You Choose a Loyalty Platform With Strong Privacy Controls?

  • Ask for the certificates, the certification body, the edition of the standard and the scope, then check the scope covers the service you would actually use.
  • Ask where data is stored and processed, and whether the vendor can meet your data residency requirements.
  • Ask what personal data the platform needs to run the programme, and what it can run without.
  • Ask how a customer’s data is deleted on request, and how retention is enforced.
  • Ask whether every reward trigger comes from a defined rule your team can inspect, or from a model whose decision is hard to reconstruct.

That last question matters more in banking than in most sectors. In the Jenius deployment, Perx’s rules-based engine ran 13.4 million rule triggers, and each one came from a defined rule that a bank team could review. That is the kind of explainability a risk committee can sign off on.

What Is the Cost Impact of Security Compliance in Loyalty Platforms?

The cost of maintaining certifications sits with the vendor, and it shows up in the price of the platform. The cost that a buyer controls is the cost of getting a platform approved. A vendor with current certificates, a clear scope statement and a documented answer to each item in a security questionnaire gives a bank’s security team less to chase, and a lighter review is cheaper for both sides.

The cheaper-looking option can cost more. A platform that cannot show certification, or cannot show that it covers your data residency needs, tends to surface those gaps late in procurement, when changing course is expensive. The sensible comparison is total cost to approve and run, not licence price alone.

Which Loyalty Platforms Have Built-In Compliance and Data Minimization?

The table below sets out what three vendors state publicly about certification and data protection. Every entry comes from the vendor’s own public pages. Buyers should confirm each claim, and its scope, directly with the vendor during due diligence.

Platform Security certifications stated publicly Data protection practices stated publicly
Perx ISO/IEC 27001 and ISO 27018 certified cloud solution (stated on perxtech.com) One example of the underlying controls: a maker-checker workflow for governed changes. The certifications themselves cover a broader control set, including access management, encryption, and incident response, not this one feature alone.
Antavo ISO 27001 (certified January 2022), and adherence to ISO 27017 and ISO 27018 (antavo.com security page) TLS 1.2 or higher in transit, encrypted volumes at rest, defined data retention policies, GDPR and UK GDPR compliance, least-data principle (antavo.com security and data management pages)
Comarch ISO/IEC 27001 certificates published for specific Comarch entities and data centres (comarch.com quality page); scope is entity-specific, so confirm it covers the loyalty service you would buy Security protocols, regular penetration testing, multi-factor authentication, GDPR compliance and anonymization processes (comarch.com loyalty management page)

Sources: perxtech.com; antavo.com/technology-integrations/security and antavo.com data management and compliance page; comarch.com/company/quality and comarch.com loyalty management page. Vendor pages change, so re-check before relying on any entry.

Perx is also working on the next phase of the platform, which is focused on additional deployment options for banks with strict data residency requirements.

FAQs:

What are best practices for loyalty platform security and privacy?
Independent certification, cloud personal data protection, encryption in transit and at rest, role-based access with maker-checker control, an audit trail, data minimization with defined retention, and regular penetration testing.
ISO 27001 sets requirements for an information security management system. ISO 27018 is a code of practice for protecting personally identifiable information in public cloud services. Buyers should look for both.
Ask for certificates with their edition and scope, where data is stored, what personal data the platform needs, how deletion works, and whether reward triggers come from inspectable rules.
Certification costs sit with the vendor and are reflected in price. The buyer’s cost is the cost of approval, which is lower when the vendor can show current certificates and clear scope. Compare total cost to approve and run, not licence price alone.
Perx describes itself as an ISO/IEC 27001 and ISO 27018 certified cloud solution. Buyers can request the certificates and their scope during due diligence.
Because every reward trigger comes from a defined rule, a bank’s risk team can review it, test it and explain it. In the Jenius deployment, 13.4 million rule triggers ran on that basis.

Praveen Vadla

Praveen Vadla is Senior Digital Marketing Manager at Perx Technologies. With over 10 years of experience in B2B SaaS marketing across the US and Southeast Asia, he focuses on customer loyalty, engagement, and retention strategy. He writes on how brands build lasting customer relationships in a mobile-first economy. Connect with Praveen on LinkedIn.

Recommended for you

Loyalty Engagement Platform Built for the Mobile-first Economy
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.