Security & Compliance

Gapp Group is committed to maintaining high standards of security, availability, and data protection across our eCommerce, incentive, and loyalty solutions.

Our security program is built on industry-recognized frameworks, independent assurance, and continuous risk management practices.


Frameworks & Regulatory Alignment

Gapp Group’s security and privacy practices are aligned with recognized industry standards and global privacy regulations, including:


SOC 2 Type II Attestation

Gapp Group has successfully completed a SOC 2 Type II
examination covering the Security Trust Services Criteria.

The audit evaluated the suitability of the design and
operating effectiveness of our controls over the period:

The examination was performed by A-LIGN, an independent CPA firm, in accordance with AICPA attestation standards.

Our SOC 2 Type II report is available upon request under NDA.

Request the SOC 2 report: security@gappgroup.com


Security Program Overview

Our security program includes documented administrative, technical, and physical safeguards designed to protect customer information and system integrity.

Key components include:


Cloud & Infrastructure Security

Gapp Group’s infrastructure is hosted on Amazon Web Services (AWS).

We leverage AWS services and security capabilities to support:


Privacy & Data Protection

Gapp Group is committed to responsible handling of personal data and supporting our customers’ privacy obligations.

GDPR

Where applicable, Gapp Group supports customers’ obligations under the General Data Protection Regulation (GDPR), including:

CCPA

Gapp Group supports customers’ compliance with the California Consumer Privacy Act (CCPA) by:


Payment Security

Gapp Group integrates with PCI-compliant payment processors and service providers to facilitate secure payment transactions.

While payment processing environments may be managed by third-party providers, Gapp Group implements controls designed to protect payment-related data within the scope of our services.

Customers remain responsible for understanding and managing their own PCI obligations as applicable.


Incident Response

Gapp Group maintains documented incident response and escalation procedures designed to:


Vendor & Third-Party Risk Management

We evaluate vendors and subservice organizations during onboarding and on an ongoing basis.

Our vendor management program includes:


Security & Compliance FAQs

What SOC 2 report does Gapp Group maintain?

The most effective customer loyalty program depends on your audience, business model, and engagement goals. Points-based, tiered, and hybrid loyalty programs are among the most widely adopted and successful structures, especially when aligned with clear incentives and performance metrics.

Does Gapp Group comply with GDPR and CCPA?

Gapp Group supports customers’ compliance with applicable privacy regulations through contractual commitments, technical safeguards, and operational controls. We act as a service provider/processor as defined in customer agreements.

How does Gapp Group protect data in the cloud?

Our infrastructure is hosted on AWS and includes network security controls, encryption in transit, monitoring tools, access controls, and change management procedures. These controls are subject to independent testing under our SOC 2 Type II examination.


Request the SOC 2 Report

Gapp Group’s SOC 2 Type II report is available to prospective customers and partners under NDA.

To request a copy of the report or submit a vendor security questionnaire: security@gappgroup.com

Our team will respond promptly to support your compliance and procurement review process.