Antavo · Trust Center
Antavo Trust Center
Trust center
Antavo maintains a public trust center documenting ISO 27001, ISO 27017, ISO 27018, and GDPR / UK GDPR compliance.
LoyaltyCustomer LoyaltyRewardsEnterpriseHeadlessRetailMarketingEngagementPromotionsGamificationEventE-CommerceCouponsPointsMembership
Certifications & Compliance
ISO 27001ISO 27017ISO 27018GDPR / UK GDPR
Source
Trust Center
generated: '2026-08-13'
method: searched
probe: true
url: https://antavo.com/product/loyalty-engine/technology/security/
model: security-and-compliance-page
note: >-
Antavo runs no dedicated trust portal - trust.antavo.com does not resolve
(DNS NXDOMAIN) and /trust-center/, /compliance/ and /security/ on the
corporate site all return 404. What it does publish is a product security and
compliance page under the Loyalty Engine technology section, which names its
certifications explicitly. That page is the compliance evidence recorded here
and is the URL the `Compliance` pointer in apis.yml addresses. No audit report,
SOC 2 attestation, sub-processor list or certificate registry number is
published, and no automated evidence-sharing portal (Vanta/Drata/SafeBase
style) was found.
certifications:
- id: iso-27001
name: ISO 27001
claimed: true
evidence: >-
"Antavo is proudly compliant with one of the strictest information security
standards, ISO 27001."
certificate_published: false
- id: iso-27017
name: ISO 27017
claimed: true
evidence: >-
"Antavo also adheres to the ISO 27017 standard, to create and maintain a
safe cloud environment."
certificate_published: false
- id: iso-27018
name: ISO 27018
claimed: true
evidence: >-
"Antavo is compliant with ISO 27018, an international standard to protect
personal data in cloud storage."
certificate_published: false
- id: gdpr
name: GDPR / UK GDPR
claimed: true
evidence: >-
"Antavo is compliant with GDPR and the UK version of the GDPR to establish
the highest of data privacy standards."
certificate_published: false
not_claimed:
- SOC 2
- PCI DSS
- HIPAA
- FedRAMP
- CSA STAR
- FIPS 140
security_practices:
encryption_in_transit: TLS 1.2 or higher
encryption_at_rest: encrypted volumes
access_control: [SSO, MFA, RBAC]
vulnerability_testing: >-
Regular testing of Antavo's own codebase and IT infrastructure for known and
0-day vulnerabilities.
penetration_testing: >-
Completed with independent third parties. No report or cadence is published.
personnel: [information security officer, data protection officer]
hosting: Google Cloud Platform, with network segregation and application firewalls
related_pages:
- url: https://antavo.com/product/loyalty-engine/technology/data-management-and-compliance/
title: Data management and compliance
- url: https://antavo.com/legals/privacy/
title: Privacy Policy
- url: https://antavo.com/legals/vulnerability-disclosure-policy/
title: Vulnerability Disclosure Policy (declines to operate a program - see security/antavo-vulnerability-disclosure.yml)
- url: https://developers.antavo.com/docs/getting-started
title: Developer documentation - data compliance section
evidence:
- source: https://antavo.com/product/loyalty-engine/technology/security/
http_status: 200
fetched: '2026-08-13'
keywords: [iso 27001, iso 27017, iso 27018, gdpr, encryption, penetration test, rbac, mfa]
- source: https://trust.antavo.com/
http_status: 0
fetched: '2026-08-13'
finding: DNS does not resolve
- source: https://antavo.com/trust-center/
http_status: 404
fetched: '2026-08-13'
- source: https://antavo.com/compliance/
http_status: 404
fetched: '2026-08-13'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/antavo-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.