Skip to trust center content

Trust & Reliability Center

Trust is a record, not a badge.

See what Loyumi implements today, what its internal tests exercise, what evidence work is planned, and what still requires an independent reviewer. A product control is not presented as a certification.

Read the labels literally

Four evidence states

  • Implemented

    Present in the current product or its published contract.

  • Tested internally

    Exercised by Loyumi’s automated or documented tests; not a third-party assurance opinion.

  • Planned

    Identified evidence or control work with no delivery date promised here.

  • Requires independent validation

    Not established by Loyumi’s own code or statements; buyers should require external evidence.

Assurance boundary

No borrowed credibility.

Loyumi does not claim a SOC 2 report, comparable security certification, independent penetration-test result, contractual uptime SLA, published RPO/RTO, production customer scale, or independently validated performance benchmark on this page. Internal tests show what the software is designed to do; they do not replace external assurance.

Production decision

Nine gates. Evidence decides.

A gate passes only when its named, dated artifact matches the intended production workload and contract. Product implementation, internal testing, and independent assurance are shown separately.

No automatic pass is claimed.“Implemented” means product evidence exists. It does not replace buyer validation, an executed contract, or an independent opinion.
  1. 01Implemented

    Complete value lifecycle

    Product evidence available; deployed proof still required

    Current record

    The 121-operation Public API 1.13 contract across 106 paths covers identity and enrollment, commerce and returns, governed value, Reward Gifts, partner exchange, disputes, exact ledger-close evidence, and 40 privacy-minimized webhook event types. Private ledger concepts are not counted as public support.

    Evidence required to pass

    A deployed OpenAPI contract, contractually supported operation list, runtime checks, and lifecycle tests that all agree.

  2. 02Tested internally

    Correctness

    Internal evidence only

    Current record

    Automated internal coverage exercises idempotency, balanced ledger postings, returns, point lots, inventory, tenant boundaries, and redemption state guards. A program-period close report now produces an exact member roll-forward, double-entry control totals, policy valuation, and deterministic SHA-256 evidence hash. No independent production-shaped or auditor-attested report is claimed.

    Evidence required to pass

    Dated duplicate, concurrency, replay, out-of-order, partial-return, and double-redemption results using the buyer's critical journeys.

  3. 03Requires independent validation

    Performance

    Open

    Current record

    A repeatable sustained-and-burst probe now reports achieved rate, success rate, p50/p95/p99, and the 3× phase. The standard credential limit remains 600 requests per minute, and no production-topology result is published.

    Evidence required to pass

    Sustained and burst results at the buyer's expected peak with at least 3× headroom, p50/p95/p99 latency, error rate, and test topology.

  4. 04Requires independent validation

    Security

    Open

    Current record

    Application security controls and internal tests are documented. No current independent penetration-test report or remediation attestation is claimed.

    Evidence required to pass

    A scoped independent penetration test, dated executive summary, finding severity record, and evidence that material findings were remediated or accepted.

  5. 05Planned

    Compliance

    Open

    Current record

    A least-privilege public operation tombstones the member profile, scrubs known structured identifier copies, and governance-scrubs affected idempotency receipt response snapshots while preserving operation identity. Ledger, transaction, consent, audit, and merchant-supplied records remain subject to documented retention. No SOC 2 report, DPA, subprocessor list, retention schedule, or operating deletion evidence is claimed.

    Evidence required to pass

    An approved assurance roadmap or report, signed DPA, current subprocessors, data map, retention schedule, deletion controls, and operating evidence.

  6. 06Requires independent validation

    Reliability

    Open

    Current record

    No public contractual SLA, uptime history, witnessed restoration result, RPO/RTO, incident escalation commitment, or disaster-recovery test is claimed.

    Evidence required to pass

    Executed SLA and support schedule, backup scope, witnessed restore evidence, measured RPO/RTO, escalation path, and a dated DR exercise.

  7. 07Tested internally

    Portability

    Internal export evidence; independent reconstruction open

    Current record

    Portability export 1.6 covers 53 environment-scoped business-state collections, including durable Reward Gifts evidence. API 1.13 retains the staged, inspectable, resumable member opening-balance import without overwriting existing members. In Production, requesting activation atomically seals the reconciled import set and permanently closes that window; rejected approval, evidence expiry, and critical incident locks do not reopen it. A reference reconstruction rejects missing links and unbalanced value. Security, identity, bearer-code, webhook-delivery, replay-cache, gift-authority, and access-role records are not transferred and carry explicit drain, re-entry, or reissue actions; full historical import and independent buyer reconstruction are not claimed.

    Evidence required to pass

    A full export, control totals, successful independent reconstruction, ledger reconciliation, timed exit rehearsal, and confirmed deletion obligations.

  8. 08Requires independent validation

    Customer evidence

    Open

    Current record

    No named production customers or reference conversations of comparable scale and complexity are claimed on this site.

    Evidence required to pass

    At least two buyer-approved reference conversations covering comparable lifecycle complexity, traffic, operating model, reconciliation, and incident history.

  9. 09Requires independent validation

    Commercial protection

    Open until contract execution

    Current record

    The site describes a commercial model but does not publish an executed order form, final pricing schedule, support commitment, liability allocation, or termination-assistance terms.

    Evidence required to pass

    Executed pricing and support schedules, liability and security terms, change control, termination assistance, data-exit rights, deletion duties, and transition pricing.

Control record

What exists—and where proof stops

These statements are deliberately narrow. “Implemented” describes an application control, not the operating effectiveness of an entire production service.

01

Application security

Secrets have defined boundaries.

  • Implemented

    Protected application secrets

    OAuth access and refresh tokens are configured for application-level encryption. Stored webhook secrets use AES-GCM. API credentials are stored as one-way hashes, carry environment-bound scopes, and can be revoked. Deleted-member suppression and automatic maintenance each require a separate server-only, non-placeholder secret of at least 32 characters. The suppression secret must remain stable unless a governed token re-hash migration is performed.

  • Tested internally

    Cryptographic behavior

    Internal tests cover webhook secret encryption/decryption and signed delivery behavior. Widget session codes are hashed, short-lived, and exchanged for permission-bound signed sessions.

  • Requires independent validation

    End-to-end security assurance

    Key custody, rotation operations, infrastructure encryption, network controls, dependency risk, and the deployed attack surface require an independent architecture review and penetration test.

02

Identity & authorization

Access is scoped by organization, environment, role, and credential.

  • Implemented

    Human and machine access

    The merchant console supports Google, Apple, and ChatGPT-backed sign-in. Organization membership is separate from identity, role-to-action rules gate operator changes, and API credentials are restricted by environment and scope.

  • Implemented

    Bounded operator-session defaults

    Console sessions use an eight-hour idle expiry, a 30-minute refresh cadence, and a 15-minute freshness window for sensitive actions. These are product defaults, not a claim of organization-configurable enterprise session policy.

  • Implemented

    Audited access-review export

    Organization owners and administrators can export a CSV of operator identity, email, effective role, ownership or membership source, and relevant timestamps. The export action creates an audit event; it is evidence input, not a completed periodic access-certification workflow.

  • Tested internally

    Separation of duties

    Automated internal tests exercise role boundaries, including separation between finance and risk actions, and permission checks around widget publishing and redemption enablement. Adjustment approval also compares an immutable stable human or service principal: another credential bound to the requester's same principal cannot approve, and an unbound legacy credential fails closed until rotated.

  • Planned

    Enterprise identity evidence

    SAML or OIDC enterprise SSO, SCIM, organization-enforced MFA, configurable session policy, IP restrictions, periodic access certification, emergency-access procedures, customer-managed keys, and a documented SIEM feed are not represented as available here.

03

Tenant isolation

Cross-tenant identifiers are treated as not found.

  • Implemented

    Shared authorization gate

    Existing objects addressed by merchant mutations are checked against both organization and environment ownership before use. Sandbox and production have separate identifiers and credentials.

  • Tested internally

    Negative-access cases

    Internal tests attempt cross-organization and cross-environment object access across supported resource types and verify rejection, alongside same-tenant success cases.

  • Requires independent validation

    Deployed isolation

    Source-level gates are not a substitute for a deployed architecture review, adversarial tenant testing, database policy review, and ongoing access-log analysis.

04

API & value correctness

Retries preserve intent; ledger changes preserve evidence.

  • Implemented

    Correctness controls

    Supported write APIs require idempotency keys, bind repeat requests to the original operation, and return trace identifiers. Ledger postings use balanced debit/credit lines, database constraints reject invalid amounts, and reversals preserve the original record instead of overwriting it. Member identity creation is separate from explicit program enrollment; value-entry mutations recheck active enrollment at the database write boundary. Governed unenrollment requires zero available, pending, and reserved balances and retains financial and consent history.

  • Tested internally

    Failure-shaped test coverage

    Internal tests cover balanced earning and redemption, invalid ledger lines, repeated requests, returns, point-lot allocation, rate limits, tenant boundaries, finite inventory guards, permission-bound redemption, exact large-integer close arithmetic, member roll-forward exceptions, double-entry exceptions, and canonical evidence hashing.

  • Implemented

    Finance-close control evidence

    The public ledger-close report is scoped to one program and one half-open period. It returns decimal-string point totals, movement by event type, finance-policy assumptions, journal mapping, readiness checks, and a SHA-256 evidence hash. It explicitly marks itself as system-generated, not independently audited and not a contractual financial statement.

  • Planned

    Production-shaped proving

    Add published concurrency, replay, out-of-order event, expiration-batch, import/export, and failure-injection reports using a workload tied to an actual buyer’s expected peak.

05

Reliability, backups & recovery

Recovery claims must come from recovery evidence.

  • Implemented

    Operational building blocks

    Request IDs, audit events, reversible credential state, rate limiting with Retry-After guidance, reconciliation concepts, and production-readiness gates support controlled operation and investigation. The checked-in worker also runs bounded maintenance after API traffic and from a per-minute scheduled trigger. A D1 per-environment lease prevents overlapping workers from owning the same sweep, and records last start, successful completion, and bounded error evidence. It requires a dedicatedMAINTENANCE_SECRET and safely does no work when the secret is missing or a placeholder.

  • Planned

    Restore and continuity evidence

    Document the backup scope and cadence, run a measured restore drill, record recovery dependencies, define evidence-based RPO/RTO, and exercise provider or regional failure before making resilience commitments.

  • Requires independent validation

    Availability and disaster recovery

    No public uptime history, contractual SLA, backup restoration result, RPO/RTO, multi-region failover claim, or disaster-recovery exercise is established here. Source-level scheduling does not prove deployed cron execution, maximum processing or delivery time, external monitoring, or paging. Buyers should treat these as open production gates.

06

Privacy & data lifecycle

Consent is recorded; lifecycle assurance is incomplete.

  • Implemented

    Consent and response handling

    Member records carry consent state, consent events preserve changes, and member API responses are marked no-store. Public Academy credentials are created only after explicit publication consent and retain the captured consent version.

  • Implemented

    Audited member anonymization

    A dedicated least-privilege operation tombstones the member profile, scrubs known structured identifier copies from operational records, and governance-scrubs stored idempotency receipt response snapshots that contain those identifiers while retaining the receipt's operation identity. Governed ledger, transaction, consent, and audit history remains explainable; merchant-supplied references or evidence remain governed by the merchant's retention policy. The operation does not promise global de-identification of arbitrary free text. Suppression tokens use a dedicated stable server-onlyPRIVACY_SUPPRESSION_SECRET of at least 32 non-placeholder characters. Public materials do not claim customer-managed key custody or an independently validated rotation ceremony.

  • Planned

    Lifecycle documentation

    Publish a data inventory, purpose and retention schedule, deletion and correction process, subprocessor register, cross-border treatment, and a data-processing agreement suitable for buyer review.

  • Requires independent validation

    Privacy operating effectiveness

    Data deletion, retention enforcement, subject-request handling, legal-basis mapping, and subprocessor controls need legal review and operating evidence; no privacy certification is claimed.

07

Portability & exit

Exports exist; independent reconstruction is the proof.

  • Implemented

    Current export and member-import surfaces

    A dedicated exports:read scope can produce a versioned, tenant-scoped JSON bundle. Its manifest declares the included collections and exclusions, and every export request is audited. Public API 1.13 also stages, inspects, and applies member opening balances in resumable, idempotent chunks without overwriting existing members. The published schemas—not a marketing list—define both portable records.

  • Tested internally

    Deterministic and secret-safe contract

    Internal contract tests cover stable ordering, pagination, organization and environment scoping, nested secret removal, URL-credential redaction, sensitive collection exclusions, and the required migration dataset.

  • Requires independent validation

    Migration rehearsal

    A buyer should perform a timed export, independently reconcile it, rebuild required state outside Loyumi, and verify contractual data-return and deletion duties before production adoption. Exact cross-request export snapshots, historical transaction and configuration import, independent reconstruction, and verified deletion remain open evidence.

Independent assurance

What would materially strengthen the record

These are evidence gates, not badges to add to a landing page. Each item should produce a dated artifact that a buyer can review.

  1. 01

    Independent security review

    Complete a scoped penetration test and close material findings.

  2. 02

    Measured recovery drill

    Restore production-shaped data and publish sanitized results plus RPO/RTO.

  3. 03

    Workload evidence

    Exercise concurrency, replay, returns, batches, and peak promotion traffic.

  4. 04

    Complete portability

    Prove that a full, reconcilable system record can leave the platform.

  5. 05

    Operational assurance

    Publish incident, privacy, subprocessor, support, and continuity evidence.

  6. 06

    Formal attestation

    Pursue appropriate external assurance only after controls operate consistently.

  7. 07

    Comparable customer evidence

    Enable two buyer-approved reference conversations at comparable complexity.

  8. 08

    Privacy and compliance packet

    Provide a DPA, subprocessors, retention and deletion controls, and assurance roadmap.

  9. 09

    Commercial exit protection

    Execute support, liability, termination assistance, and data-exit commitments.

Incident reporting

Contain first. Preserve evidence.

A dedicated public security-reporting mailbox and response-time commitment are not verified on this site. Customers with an active engagement should use their named Loyumi contact or authenticated support channel. No public acknowledgement time is promised here.

Read the published incident runbook

Include in an initial report

  • A concise summary and observed impact
  • Affected organization and environment, without secrets
  • Relevant request IDs and UTC timestamps
  • A safe reproduction or evidence-preservation note

Do not send passwords, API keys, raw production exports, or unnecessary personal data in the first message.

Buyer evidence packet

One reviewable index

Use this index before material customer value or financial liability is placed on the platform. Ask for each artifact by name and record the document version, owner, review date, and approval decision.

Loyumi production gates, current evidence, and required pass artifacts
GateEvidence stateCurrent recordEvidence required to pass
Complete value lifecycleImplementedThe 121-operation Public API 1.13 contract across 106 paths covers identity and enrollment, commerce and returns, governed value, Reward Gifts, partner exchange, disputes, exact ledger-close evidence, and 40 privacy-minimized webhook event types. Private ledger concepts are not counted as public support.A deployed OpenAPI contract, contractually supported operation list, runtime checks, and lifecycle tests that all agree.
CorrectnessTested internallyAutomated internal coverage exercises idempotency, balanced ledger postings, returns, point lots, inventory, tenant boundaries, and redemption state guards. A program-period close report now produces an exact member roll-forward, double-entry control totals, policy valuation, and deterministic SHA-256 evidence hash. No independent production-shaped or auditor-attested report is claimed.Dated duplicate, concurrency, replay, out-of-order, partial-return, and double-redemption results using the buyer's critical journeys.
PerformanceRequires independent validationA repeatable sustained-and-burst probe now reports achieved rate, success rate, p50/p95/p99, and the 3× phase. The standard credential limit remains 600 requests per minute, and no production-topology result is published.Sustained and burst results at the buyer's expected peak with at least 3× headroom, p50/p95/p99 latency, error rate, and test topology.
SecurityRequires independent validationApplication security controls and internal tests are documented. No current independent penetration-test report or remediation attestation is claimed.A scoped independent penetration test, dated executive summary, finding severity record, and evidence that material findings were remediated or accepted.
CompliancePlannedA least-privilege public operation tombstones the member profile, scrubs known structured identifier copies, and governance-scrubs affected idempotency receipt response snapshots while preserving operation identity. Ledger, transaction, consent, audit, and merchant-supplied records remain subject to documented retention. No SOC 2 report, DPA, subprocessor list, retention schedule, or operating deletion evidence is claimed.An approved assurance roadmap or report, signed DPA, current subprocessors, data map, retention schedule, deletion controls, and operating evidence.
ReliabilityRequires independent validationNo public contractual SLA, uptime history, witnessed restoration result, RPO/RTO, incident escalation commitment, or disaster-recovery test is claimed.Executed SLA and support schedule, backup scope, witnessed restore evidence, measured RPO/RTO, escalation path, and a dated DR exercise.
PortabilityTested internallyPortability export 1.6 covers 53 environment-scoped business-state collections, including durable Reward Gifts evidence. API 1.13 retains the staged, inspectable, resumable member opening-balance import without overwriting existing members. In Production, requesting activation atomically seals the reconciled import set and permanently closes that window; rejected approval, evidence expiry, and critical incident locks do not reopen it. A reference reconstruction rejects missing links and unbalanced value. Security, identity, bearer-code, webhook-delivery, replay-cache, gift-authority, and access-role records are not transferred and carry explicit drain, re-entry, or reissue actions; full historical import and independent buyer reconstruction are not claimed.A full export, control totals, successful independent reconstruction, ledger reconciliation, timed exit rehearsal, and confirmed deletion obligations.
Customer evidenceRequires independent validationNo named production customers or reference conversations of comparable scale and complexity are claimed on this site.At least two buyer-approved reference conversations covering comparable lifecycle complexity, traffic, operating model, reconciliation, and incident history.
Commercial protectionRequires independent validationThe site describes a commercial model but does not publish an executed order form, final pricing schedule, support commitment, liability allocation, or termination-assistance terms.Executed pricing and support schedules, liability and security terms, change control, termination assistance, data-exit rights, deletion duties, and transition pricing.

Deployment decision

Start with evidence-sized risk.

The current record supports a controlled technical pilot with synthetic or nonfinancial value and explicit success gates. It does not, by itself, establish enterprise production readiness for material customer value, cashback, transferable points, or accounting liability.

Production approval should follow your security, privacy, legal, finance, reliability, and exit reviews—not this page’s design or wording.