Compliance

SOC 2 & ISO 27001 Compliance

LocalReach Rewards is committed to meeting the highest standards for information security. We are actively pursuing SOC 2 Type II and ISO 27001 certifications, building on a security-first architecture that already enforces encryption, access control, and audit logging.

In Progress

SOC 2 Type II

SOC 2 Type II evaluates how well our controls operate over time, covering the Trust Service Criteria of Security, Availability, Processing Integrity, Confidentiality, and Privacy.

  • Role-based access control with least-privilege enforcement
  • Row-Level Security at the database layer preventing tenant data leakage
  • Append-only audit logs capturing every privileged action
  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Documented incident response and vulnerability disclosure process
  • Quarterly access reviews and onboarding/offboarding procedures
In Progress

ISO 27001

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). We are building our ISMS around risk assessment, documented policies, and continuous improvement.

  • Information security policy approved by leadership
  • Asset inventory and classification of data types
  • Risk assessment methodology with periodic review
  • Supplier and third-party security due diligence
  • Business continuity and disaster recovery planning
  • Internal audits and management review cycles
Shared Controls

Controls supporting both frameworks

Many of our existing controls map directly to both SOC 2 Trust Service Criteria and ISO 27001 Annex A controls, giving us a strong foundation for both audits.

Access Control

  • Three-tier RBAC: Admin, Business, Creator
  • Row-Level Security enforced at the database layer
  • Session management via signed JWTs
  • Admin routes protected at both routing and database layers

Audit & Monitoring

  • Append-only audit_logs table — no UPDATE or DELETE policies
  • Every privileged action recorded with actor, resource, and timestamp
  • Automated fraud detection with severity logging
  • Resolution decisions audited end-to-end

Data Protection

  • TLS 1.2+ enforced with HSTS preload (2-year duration)
  • AES-256 encryption at rest via Supabase (AWS)
  • Data minimization — only coarse IP geolocation, no precise GPS
  • GDPR and CCPA data subject rights supported

Infrastructure

  • Hosted on Supabase (AWS) — ISO 27001 certified, SOC 2 Type II
  • Daily point-in-time backups with 7-day retention
  • Numbered, sequential database migration versioning
  • Dependency scanning via npm audit
Compliance Roadmap

Our path to certification

We are following a phased approach to achieve and maintain SOC 2 and ISO 27001 certification.

Gap Analysis & Scoping

Completed

Identify control gaps against SOC 2 and ISO 27001 requirements.

2

Policy Documentation

In Progress

Formalize information security policies, access procedures, and incident response plans.

3

Control Implementation

In Progress

Operationalize remaining controls and evidence collection workflows.

4

Internal Audit

Upcoming

Run internal audits to validate controls before external assessment.

5

External Audit (SOC 2 Type I)

Upcoming

Engage a third-party auditor for SOC 2 Type I attestation.

6

Surveillance & Continuous Improvement

Upcoming

Ongoing monitoring, annual reviews, and progression toward Type II.

Subprocessors & Data Handling

We rely on trusted, certified subprocessors to deliver our service. Each subprocessor is bound by a Data Processing Agreement and reviewed annually.

SubprocessorPurpose
Supabase (AWS)Database, auth, storage
Vercel / NetlifyApplication hosting & CDN
IP Geolocation APICoarse location for scoring

We do not sell personal data. Location data is limited to city/state/country granularity and is used solely for engagement scoring. See our Privacy Policy for full details.

Request a Compliance Report

Existing and prospective enterprise customers can request our current security documentation, including our compliance roadmap and control matrix.