Security

Program data deserves clear boundaries.

This overview describes the controls Incenify uses today to limit access, protect program information, and support customer security review.

Current control scope

Access

Role, tenant, account status, and session checks

Program data

Limited to what each configured workflow needs

Proof files

Private storage with server-mediated access

Review

Vendor questionnaires and specific requirements handled directly

Current controls

Security follows the program record from access through outcome.

01

Data minimization

Incenify is designed to collect the account, eligibility, activity, reward, and communication data required to operate a configured incentive program. Depending on the workflow, that can include a participant's name, work email, role, partner affiliation, program activity, and an optional mobile number.

The platform is not designed to store payment-card data, Social Security numbers, health information, or biometric data. Uploaded receipts and invoice files are treated as confidential program evidence.

02

Identity and access

Application sessions are signed and checked against the current user's account status, role, tenant, and session revocation state. Participant, partner, and administrative areas are role-gated, and privileged operations run through server-side services.

Registration does not automatically create active program access. Email verification, tenant and audience rules, account status, and administrative approval can be applied before access is granted.

03

Tenant and storage boundaries

Program records are tenant-scoped. Server-side tenant filtering is the primary application control for privileged workflows, with database row-level policies used as an additional boundary where applicable.

Sales-claim proof files are stored in private object storage and delivered through signed or server-mediated access rather than public file URLs. Service credentials are kept out of browser code.

04

Encryption and infrastructure

Customer data is encrypted in transit and at rest through the managed infrastructure used for hosting, authentication, database, and storage services. Production access is restricted to the people and services that need it to operate or support the platform.

Incenify relies on managed infrastructure providers instead of maintaining payment-card, database, or authentication infrastructure directly.

05

Backups and retention

Production database records are backed up daily through the managed database backup service and retained for 30 days. Uploaded files are maintained separately in private object storage and are not restored through a database backup.

Program data is retained for the period required to operate the service, preserve program and audit history, and meet contractual or legal obligations. Return and deletion requirements are handled through the applicable agreement.

06

Audit and incident handling

Key privileged actions—including access decisions, claim review, and configuration changes—write structured records that support investigation and operational review. Security-relevant changes are checked through test, build, database-policy, and protected-route validation before release.

Confirmed incidents involving unauthorized access to customer data are assessed and communicated without unreasonable delay in line with the applicable agreement.

Customer diligence

Bring the requirements that matter to your program.

We respond to reasonable vendor questionnaires and can address data handling, access, retention, and workflow-specific requirements during diligence.