Sondar LogicBook a Demo
SECURITY

Security and infrastructure

A rebate programme hands a processor receipt images and claimant contact details. This page sets out how that is protected, where it is held, and who can reach it.

Encryption and transport

The audit trail is worth a line of its own. Every decision the engine reaches is stored with the rule it applied and the evidence it applied it to, which is what lets a disputed rejection be answered months later without reopening the whole file.

  • AES-256 encryption for all data at rest, including receipt images.
  • TLS 1.2 or higher for all data in transit, with no unencrypted fallback.
  • Access to production data is limited to named accounts and logged.
  • Every claim decision is retained with its reason and a full audit trail.

Infrastructure and certification

The platform runs on SOC 2 Type II certified infrastructure, hosted in Canada, with the controls that certification covers applying to the hosting layer.

If your procurement process requires a vendor level report in addition to that, raise it at the start of the conversation so it can be handled in the pilot agreement rather than late in a security review.

For most rebate programmes the questions that decide the review are where the data sits, how it is encrypted, who can reach it and how long it is kept. Those are answered above and on the PIPEDA page.

Data residency and isolation

Claim records and claimant personal information are stored in Canada and the platform runs in Canada. Receipt images are never stored anywhere. Reading the text off a receipt is done by a processing provider outside Canada, in the moment, and can be moved into Canada for a programme that requires it. Client programmes are isolated from one another, and no client's claim data is used to inform another client's programme.

SondarLogic never receives, holds or transmits funds. Rewards are funded and released from the client's own account, so there is no payment float and no stored payment credential to protect.

Fraud controls

Duplicate submissions, altered images, templated claims and screenshots of other people's claims are caught before payment rather than found in a reconciliation months later.

We describe what the controls catch rather than how they decide, because a published method is a method somebody works around.

Common questions

What are your security certifications?

The platform runs on SOC 2 Type II certified infrastructure, hosted in Canada, with AES-256 encryption at rest and TLS 1.2 or higher in transit. If your procurement requires a vendor level report as well, raise it early so it can be handled in the pilot agreement.

How is data encrypted?

AES-256 at rest, including receipt images, and TLS 1.2 or higher in transit with no unencrypted fallback.

Where is the data hosted?

On servers in Canada, and the platform runs in Canada. Receipt images are never stored anywhere. The one step outside Canada is reading the text off the receipt, done in the moment by a processing provider that does not keep the image, and that can be moved into Canada for a programme that requires it.

Do you hold payment credentials or funds?

No. Rewards are funded and released from the client's own account. SondarLogic never receives, holds or transmits money, so there is no float and no stored payment instrument.

Is one client's data visible to another?

No. Programmes are isolated, and claim data from one client is never used to inform another client's programme or reporting.

Do you have a Master Service Agreement?

Yes. There is a standard, pre vetted MSA so legal reviews it once rather than negotiating from scratch per programme.

RELATED
PIPEDA and data residencyHow receipt validation worksRebate processing explainedPrivacy PolicyTerms of Service

Receipt in. Reward out. The same day.

See the engine decide a real claim, and see everything it hands back besides the decision.

Book a Demo partnership@sondarlogic.com
← Back to sondarlogic.com