Security & Compliance
Security Built Into Every Layer
Protecting your data, your brand, and your recipients is foundational to Catalog API. We pair independently audited controls with privacy-by-design engineering so you can deliver rewards with confidence at any scale, anywhere in the world.
Certifications & Compliance
Catalog API is built to meet the standards enterprise programs require. Our compliance posture is reviewed regularly and backed by independent audits.
SOC 2 Type II
Independently audited against the AICPA Trust Services Criteria for security, availability, and confidentiality. The audit evaluates our controls and confirms they operate effectively over time.
GDPR
Practices aligned with the EU General Data Protection Regulation, including lawful processing, data-subject rights, and data-handling commitments.
HIPAA
Controls that support health & wellness programs handling sensitive data, with safeguards appropriate to protected health information.
CCPA / CPRA
Support for California consumer privacy rights. See our California Privacy Notice for details.
Trans-Atlantic Data Privacy Framework
Adherence to the EU-U.S. Data Privacy Framework for the lawful transfer of personal data across borders.
Privacy by Design
Data minimization is a default. We only store data we need to forward, and scope access to what each program requires. Read our Privacy Policy .
Data Protection
Encrypted in Transit and at Rest
Your data is protected using modern, industry-standard cryptography at every layer.
How we protect your data:
- All traffic is encrypted in transit over TLS (HTTPS only)
- Sensitive credentials are stored hashed, never in plaintext
- Webhook signing secrets encrypted at rest
- Sandbox and production are fully isolated, with separate credentials
- Strict environment separation prevents test data from reaching production
Authentication & Access Control
Authenticated, Scoped, and Revocable
Access is designed so you stay in control of your integration at all times.
Access controls include:
- API key authentication on every request
- Multi-factor authentication (TOTP) is available for accounts
- Zero-downtime key rotation with up to two active keys per environment
- Keys can be deactivated instantly if compromised
- Per-account rate limiting to protect availability
- Least-privilege access scoped to each program
Monitoring & Accountability
Traceable and Accountable
We keep a clear record of sensitive actions so changes are traceable and accountable.
Monitoring includes:
- Audit logging of account, credential, and catalog changes
- Traceable request identifiers for support and investigation
- Continuous monitoring of platform health and usage
Reporting a Vulnerability
We welcome reports from the security community. If you believe you've found a vulnerability, please contact us at security@catalogapi.com with details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure.