SOC 2 & ISO 27001 Compliance
LocalReach Rewards is committed to meeting the highest standards for information security. We are actively pursuing SOC 2 Type II and ISO 27001 certifications, building on a security-first architecture that already enforces encryption, access control, and audit logging.
SOC 2 Type II
SOC 2 Type II evaluates how well our controls operate over time, covering the Trust Service Criteria of Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- Role-based access control with least-privilege enforcement
- Row-Level Security at the database layer preventing tenant data leakage
- Append-only audit logs capturing every privileged action
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Documented incident response and vulnerability disclosure process
- Quarterly access reviews and onboarding/offboarding procedures
ISO 27001
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). We are building our ISMS around risk assessment, documented policies, and continuous improvement.
- Information security policy approved by leadership
- Asset inventory and classification of data types
- Risk assessment methodology with periodic review
- Supplier and third-party security due diligence
- Business continuity and disaster recovery planning
- Internal audits and management review cycles
Controls supporting both frameworks
Many of our existing controls map directly to both SOC 2 Trust Service Criteria and ISO 27001 Annex A controls, giving us a strong foundation for both audits.
Access Control
- Three-tier RBAC: Admin, Business, Creator
- Row-Level Security enforced at the database layer
- Session management via signed JWTs
- Admin routes protected at both routing and database layers
Audit & Monitoring
- Append-only audit_logs table — no UPDATE or DELETE policies
- Every privileged action recorded with actor, resource, and timestamp
- Automated fraud detection with severity logging
- Resolution decisions audited end-to-end
Data Protection
- TLS 1.2+ enforced with HSTS preload (2-year duration)
- AES-256 encryption at rest via Supabase (AWS)
- Data minimization — only coarse IP geolocation, no precise GPS
- GDPR and CCPA data subject rights supported
Infrastructure
- Hosted on Supabase (AWS) — ISO 27001 certified, SOC 2 Type II
- Daily point-in-time backups with 7-day retention
- Numbered, sequential database migration versioning
- Dependency scanning via npm audit
Our path to certification
We are following a phased approach to achieve and maintain SOC 2 and ISO 27001 certification.
Gap Analysis & Scoping
CompletedIdentify control gaps against SOC 2 and ISO 27001 requirements.
Policy Documentation
In ProgressFormalize information security policies, access procedures, and incident response plans.
Control Implementation
In ProgressOperationalize remaining controls and evidence collection workflows.
Internal Audit
UpcomingRun internal audits to validate controls before external assessment.
External Audit (SOC 2 Type I)
UpcomingEngage a third-party auditor for SOC 2 Type I attestation.
Surveillance & Continuous Improvement
UpcomingOngoing monitoring, annual reviews, and progression toward Type II.
Subprocessors & Data Handling
We rely on trusted, certified subprocessors to deliver our service. Each subprocessor is bound by a Data Processing Agreement and reviewed annually.
| Subprocessor | Purpose |
|---|---|
| Supabase (AWS) | Database, auth, storage |
| Vercel / Netlify | Application hosting & CDN |
| IP Geolocation API | Coarse location for scoring |
We do not sell personal data. Location data is limited to city/state/country granularity and is used solely for engagement scoring. See our Privacy Policy for full details.
Request a Compliance Report
Existing and prospective enterprise customers can request our current security documentation, including our compliance roadmap and control matrix.