Security & Compliance
Gapp Group is committed to maintaining high standards of security, availability, and data protection across our eCommerce, incentive, and loyalty solutions.
Our security program is built on industry-recognized frameworks, independent assurance, and continuous risk management practices.



Frameworks & Regulatory Alignment
Gapp Group’s security and privacy practices are aligned with recognized industry standards and global privacy regulations, including:
- SOC 2 (Security)
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
These frameworks guide how we design, implement, and monitor our security and data protection controls.
SOC 2 Type II Attestation
Gapp Group has successfully completed a SOC 2 Type II
examination covering the Security Trust Services Criteria.
The audit evaluated the suitability of the design and
operating effectiveness of our controls over the period:
Audit Period: Aug 1 – Oct 31, 2025
Trust Services Criteria: Security

The examination was performed by A-LIGN, an independent CPA firm, in accordance with AICPA attestation standards.
Our SOC 2 Type II report is available upon request under NDA.
Request the SOC 2 report: security@gappgroup.com
Security Program Overview
Our security program includes documented administrative, technical, and physical safeguards designed to protect customer information and system integrity.
Key components include:
- Annual risk assessments
- Ongoing internal control reviews
- Defined incident response and escalation procedures
- Role-based access controls and least-privilege enforcement
- Encryption of data in transit using TLS
- Vendor and third-party risk management processes
We continuously monitor and improve our controls to maintain resilience and operational integrity.
Cloud & Infrastructure Security
Gapp Group’s infrastructure is hosted on Amazon Web Services (AWS).
We leverage AWS services and security capabilities to support:
- Network segmentation and firewall protections
- Intrusion detection and monitoring
- Logging and alerting for unusual system activity
- Encryption for defined points of connectivity
- Secure change management processes
AWS operates as a subservice organization within our SOC 2 scope, and we monitor vendor attestations and relevant controls as part of our third-party risk management program.
Privacy & Data Protection
Gapp Group is committed to responsible handling of personal data and supporting our customers’ privacy obligations.
GDPR
Where applicable, Gapp Group supports customers’ obligations under the General Data Protection Regulation (GDPR), including:
- Processing personal data in accordance with documented instructions
- Implementing appropriate technical and organizational safeguards
- Supporting data subject access, correction, and deletion requests
- Entering into Data Processing Agreements (DPAs) where required
Gapp Group acts as a service provider/processor where contractually defined and does not use customer personal data for purposes outside agreed services.
CCPA
Gapp Group supports customers’ compliance with the California Consumer Privacy Act (CCPA) by:
- Acting as a service provider under applicable agreements
- Processing personal information solely for business purposes defined in customer contracts
- Supporting customer responses to consumer rights requests, where applicable
- Implementing safeguards designed to protect personal information from unauthorized access
Gapp Group does not sell personal information.
Payment Security
Gapp Group integrates with PCI-compliant payment processors and service providers to facilitate secure payment transactions.
While payment processing environments may be managed by third-party providers, Gapp Group implements controls designed to protect payment-related data within the scope of our services.
Customers remain responsible for understanding and managing their own PCI obligations as applicable.
Incident Response
Gapp Group maintains documented incident response and escalation procedures designed to:
- Detect and analyze security events
- Classify and prioritize incidents
- Contain and remediate threats
- Communicate material service disruptions, where applicable
We conduct ongoing monitoring and maintain internal processes to track and remediate identified control gaps.
Vendor & Third-Party Risk Management
We evaluate vendors and subservice organizations during onboarding and on an ongoing basis.
Our vendor management program includes:
- Risk assessments
- Review of relevant attestations (such as SOC reports)
- Defined contractual security requirements
Security & Compliance FAQs
What SOC 2 report does Gapp Group maintain?
The most effective customer loyalty program depends on your audience, business model, and engagement goals. Points-based, tiered, and hybrid loyalty programs are among the most widely adopted and successful structures, especially when aligned with clear incentives and performance metrics.
Does Gapp Group comply with GDPR and CCPA?
Gapp Group supports customers’ compliance with applicable privacy regulations through contractual commitments, technical safeguards, and operational controls. We act as a service provider/processor as defined in customer agreements.
How does Gapp Group protect data in the cloud?
Our infrastructure is hosted on AWS and includes network security controls, encryption in transit, monitoring tools, access controls, and change management procedures. These controls are subject to independent testing under our SOC 2 Type II examination.
Request the SOC 2 Report
Gapp Group’s SOC 2 Type II report is available to prospective customers and partners under NDA.
To request a copy of the report or submit a vendor security questionnaire: security@gappgroup.com
Our team will respond promptly to support your compliance and procurement review process.