Security & Compliance

Security Built Into Every Layer


Protecting your data, your brand, and your recipients is foundational to Catalog API. We pair independently audited controls with privacy-by-design engineering so you can deliver rewards with confidence at any scale, anywhere in the world.

Certifications & Compliance

Catalog API is built to meet the standards enterprise programs require. Our compliance posture is reviewed regularly and backed by independent audits.

Certified

SOC 2 Type II

Independently audited against the AICPA Trust Services Criteria for security, availability, and confidentiality. The audit evaluates our controls and confirms they operate effectively over time.

GDPR

Practices aligned with the EU General Data Protection Regulation, including lawful processing, data-subject rights, and data-handling commitments.

HIPAA

Controls that support health & wellness programs handling sensitive data, with safeguards appropriate to protected health information.

CCPA / CPRA

Support for California consumer privacy rights. See our California Privacy Notice for details.

Trans-Atlantic Data Privacy Framework

Adherence to the EU-U.S. Data Privacy Framework for the lawful transfer of personal data across borders.

Privacy by Design

Data minimization is a default. We only store data we need to forward, and scope access to what each program requires. Read our Privacy Policy .


Data Protection

Encrypted in Transit and at Rest

Your data is protected using modern, industry-standard cryptography at every layer.

How we protect your data:

  • All traffic is encrypted in transit over TLS (HTTPS only)
  • Sensitive credentials are stored hashed, never in plaintext
  • Webhook signing secrets encrypted at rest
  • Sandbox and production are fully isolated, with separate credentials
  • Strict environment separation prevents test data from reaching production

Authentication & Access Control

Authenticated, Scoped, and Revocable

Access is designed so you stay in control of your integration at all times.

Access controls include:

  • API key authentication on every request
  • Multi-factor authentication (TOTP) is available for accounts
  • Zero-downtime key rotation with up to two active keys per environment
  • Keys can be deactivated instantly if compromised
  • Per-account rate limiting to protect availability
  • Least-privilege access scoped to each program

Monitoring & Accountability

Traceable and Accountable

We keep a clear record of sensitive actions so changes are traceable and accountable.

Monitoring includes:

  • Audit logging of account, credential, and catalog changes
  • Traceable request identifiers for support and investigation
  • Continuous monitoring of platform health and usage

Reporting a Vulnerability

We welcome reports from the security community. If you believe you've found a vulnerability, please contact us at security@catalogapi.com with details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure.