Corporate Gifting Stack

SOC 2 Compliance Requirements for Corporate Gifting Platforms

Vendor data controls matter more than most procurement teams think before signing.

Editor at Large · · 12 min read
Gifting Automation & Tools · September 12, 2026 · 12 min read · 2,805 words

A corporate gifting platform touches more sensitive data than most buyers realize when they're comparing pricing tiers and catalog features. SOC 2 is the audit framework that tells procurement, IT, and legal teams whether a vendor actually protects that data, and which type of report a vendor holds changes what the certification actually proves. This piece breaks down what SOC 2 requires, why the gaps between report types and criteria matter, and what to ask before a contract gets signed.

Start with what's actually flowing through these platforms. Recipient PII gets collected at volume: names, email addresses, phone numbers, home addresses, gift preferences, personal message content, survey responses, redemption history. Layer on financial asset data too. Gift card codes, prepaid balances, redemption credentials all become fraud targets the moment storage gets sloppy. Then there's the CRM pipe. Salesforce, HubSpot, Marketo, and Outreach connections are standard in this category now, which means the gifting platform sits as a working node inside the client's entire revenue stack.

That creates two distinct roles the platform plays at once. It's a controller for its own operational data: account admin, fraud prevention, internal analytics, marketing. But for program data (the recipient records, the recognition messages, the redemption activity) it's a processor, and the buying company remains the controller under whatever privacy law applies. This split isn't a technicality. It decides how liability gets divided in a contract and what a data processing agreement actually needs to say.

Gift card data carries its own weight here, and it's worth being blunt about why. When it leaks, it doesn't just embarrass a brand, it enables direct theft: a stolen gift card code is cash sitting in someone else's pocket, and the buyer eats that loss. Per IBM's 2024 Cost of a Data Breach Report, 40% of breaches involve data spread across multiple environments, and a gifting platform running CRM integrations alongside fulfillment systems fits that profile almost exactly. So before getting into what SOC 2 actually requires, sit with the stakes for a second. This is the category of vendor where "how do you handle our data" is not a box-checking question. Treat it like one, and you're the buyer explaining a breach to your own legal team six months later.

What SOC 2 is, what it measures, and why it was designed for exactly this category of vendor

SOC 2 (System and Organization Controls 2) comes from the American Institute of CPAs, and it exists to answer one question: how well does a cloud or SaaS vendor manage customer data? It's not a financial reporting framework, that's SOC 1's job. SOC 2 is about operational trust, plain and simple.

The governing standard is TSP Section 100, the 2017 Trust Services Criteria, updated with revised points of focus in 2022. That's still the standard in use. Under it, auditors check against five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only mandatory one, required in every single SOC 2 audit no matter the vendor type. The rest get chosen based on what a vendor has actually promised its customers.

Security carries 9 specific points of focus. Privacy carries additional points of focus on top of that. Worth naming those numbers up front, because these two criteria represent the heaviest lift in an audit, and they're also the two most directly relevant to a gifting platform.

Buyers get one thing wrong more than anything else: they assume "SOC 2 certified" means one fixed thing. It doesn't. Two vendors can both claim it and mean completely different things, because one covers Security alone and the other covers all five criteria. The report itself comes from an independent auditor, an attestation, not a vendor's self-description, and that's what makes the whole framework worth anything in the first place. A gifting platform is cloud-based, handles customer PII at scale, moves financial assets around, and plugs into enterprise software stacks. That's the exact profile SOC 2 was built to check.

The Type I versus Type II distinction that changes everything about what a report actually proves

Both report types are legitimate. Neither one is fake or lesser in some dishonest sense. The difference comes down to what got tested and over how long, and that difference matters more than most buyers assume when they see "SOC 2" on a vendor's homepage.

Type I is a snapshot. The auditor checks whether controls were properly designed and in place on one specific date. No observation window needed, which makes it faster and cheaper to get. Type II is different in kind, not just degree: it's an operational audit stretched across a sustained window, usually a minimum of about three months, though six to twelve is common. The auditor tests whether those controls actually held up, day after day, under real operating conditions.

Put plainly: Type I proves a policy existed on paper on a given Tuesday. Type II proves that policy survived contact with millions of API calls, data refreshes, and access requests over months. That's a meaningfully different claim, and it's exactly why most enterprise procurement teams now demand Type II as the baseline, not the exception.

Here's a red flag worth watching for: a vendor that says "SOC 2 compliant" without saying which type. That's not a small omission. It's the kind of ambiguity that should prompt a follow-up question, not a shrug, and a vendor that dodges the follow-up has told you something on its own.

Why does this matter so much specifically for gifting? Per Check Point's 2024 Cloud Security Report, 61% of companies faced a cloud security incident in 2024, and 21% of those resulted in an actual data breach. Only 4% of organizations could contain these risks quickly. That gap, between controls on paper and controls that hold up under pressure, is exactly what Type II is built to expose. Gifting platforms live and die on operational consistency: time-sensitive event sends, milestone triggers firing on someone's work anniversary, gift card disbursements that need to fire correctly at 2 a.m. on a Friday before a long weekend. A control that's well-designed but never tested under load isn't much comfort when the send fails.

The question to ask directly: does the vendor hold a SOC 2 Type II report, and what's the observation period it covers? A real answer names a specific audit window. A vague answer names a certification date and stops there.

How the five Trust Services Criteria map onto gifting platform operations, and which ones a vendor should be covering

Security, being mandatory, covers the baseline: logical access controls, authentication, system monitoring, encryption, change management. Buyers should expect concrete evidence of these controls in operation, not just policy language sitting in a PDF. One spot worth watching closely: logical and physical access controls, which fall under the Security criterion, are among the more demanding areas in a SOC 2 audit. Ask specifically how user provisioning and deprovisioning gets handled, and ask what happens on the day someone leaves the company.

Availability matters more here than it might in other SaaS categories, because gifting programs run on timing. A milestone send tied to someone's start-date anniversary doesn't get a grace period. Uptime commitments, disaster recovery plans, and capacity planning all fall under this criterion, and a platform outage during a scheduled campaign is a direct business consequence, not just an inconvenience someone shrugs off.

Processing Integrity is the one buyers underrate, and they shouldn't. It covers whether data processing is complete, accurate, and properly authorized, which is exactly the question that matters when gift card redemptions, fund disbursements, or prepaid value transfers are involved. This is the criterion auditing the financial math itself, not just the perimeter fence around it.

Confidentiality protects client-designated confidential information, and given how much CRM data (account lists, deal intelligence, pipeline detail) flows into these platforms through integrations, this criterion sits closer to the center of the risk picture than its name suggests.

Privacy is the heaviest lift, carrying its own set of points of focus, and it's arguably the most important criterion in this whole category given the sheer volume of recipient PII moving through a gifting program. It covers consent management, data retention policy, and procedures for honoring deletion requests. Because of the controller/processor split covered earlier, a vendor's Privacy controls reach directly into the client's own GDPR and CCPA exposure. Weak Privacy controls on the vendor side become the client's legal problem, not just the vendor's. That's the part procurement teams tend to miss until it's too late to renegotiate.

A gifting platform with a genuinely thorough report covers all five: Security, Availability, Processing Integrity, Confidentiality, and Privacy. A report limited to Security alone isn't automatically a dealbreaker, but it leaves real questions unanswered about how financial assets get handled and how PII gets governed. Those questions then have to get resolved through other documentation instead of the audit itself. Across first-time audits generally, vendors commonly struggle with demonstrating that controls actually operated consistently over time rather than merely existing on paper. Worth asking a vendor directly how its last audit cycle addressed those exact gaps, rather than taking the pass/fail result at face value.

Why enterprise procurement teams now treat SOC 2 Type II as a threshold condition, not a nice-to-have

SOC 2 has quietly shifted from a differentiator to table stakes for B2B SaaS vendors selling into enterprise accounts. That shift shows up in the numbers. Gartner Digital Markets data found that 46% of software buyers chose a vendor specifically because of its security certification, reputation, or data privacy practices. Security posture is a selection criterion in its own right now, not a background check that happens after the deal is basically done.

Drata's research found that 87% of companies reported losing business or facing other bad outcomes tied to weak security compliance. Separately, industry data shows over 60% of businesses say they're more likely to partner with a vendor that holds SOC 2 compliance. For companies in healthcare, financial services, or public sector work, this isn't optional at all. Their own regulatory obligations flow downstream onto every vendor they touch, gifting platform included.

There's a practical mechanic worth understanding here. A current SOC 2 Type II report lets a vendor answer huge chunks of an enterprise security questionnaire without weeks of back-and-forth emails between legal teams. That's not a minor convenience: it can be the difference between a procurement cycle closing in a month versus dragging into a quarter. And the reverse holds too. The gifting platform shows up as a third-party risk line item inside the client's own SOC 2 or ISO 27001 audit. If the platform can't produce a report on request, the client's own auditors are going to ask why an unverified vendor got picked in the first place.

PwC's 2024 Global Digital Trust Insights found that data breaches costing companies more than $1 million jumped from 27% to 36% year over year. That single number explains a lot of the tightening happening in procurement right now. Vendors without Type II certification aren't just carrying a security risk anymore. In scrutinized industries, they're a procurement delay and, quite possibly, a deal-blocker outright.

What confirmed SOC 2 status looks like in practice: the vendors the sources document

Giftbit confirmed SOC 2 compliance as of November 9, 2023, per its own announcement. The criteria named explicitly are Confidentiality, Availability, and Processing Integrity, alongside the mandatory Security criterion. On the technical side, Giftbit's documentation points to encryption in transit using TLS 1.2 or higher, encryption at rest via AES-256, AWS infrastructure with automatic redundancy, round-the-clock intrusion detection and incident response, and separate testbed and production environments. Giftbit's CPO, Bryan Dwyer, put it directly: "Having a SOC 2 compliant reward partner is the new necessity for companies that deal with sensitive data." CEO Leif Baradoy added that the certification "makes it easier for our customers to answer questions from their security and compliance teams." The company also positions itself as easing onboarding for regulated sectors: finance, securities, telecom, education, and healthcare. What's not stated anywhere in the announcement is whether the report is Type I or Type II, and that gap is worth closing directly rather than assumed away.

PerkUp holds SOC 2 Type II certification for enterprise security, per its own listing, and it's one of the few vendors in this category where the report type is actually stated up front instead of left vague. Details beyond that, the specific criteria covered, the observation window, aren't laid out in available material, so a full report request is the obvious next step for anyone evaluating them seriously.

Even where a vendor's SOC 2 status shows up in public marketing, the level of detail swings wildly. That's the pattern worth remembering here: public statements are a starting point, never a substitute for the actual report. For any vendor under evaluation, the process looks the same regardless of name. Check the vendor's official trust or compliance portal, request the current SOC 2 report directly, and confirm three things explicitly. These are the report type, the observation period, and which Trust Services Criteria are actually in scope. SOC 2 status isn't permanent, either. Certifications lapse, observation windows expire, and scope shifts between audit cycles, so "we got SOC 2 certified in 2022" without a current report attached isn't worth much by 2026.

Where SOC 2 ends and where GDPR and CCPA begin, and why a vendor can hold both while still leaving gaps

SOC 2 tells a buyer that security and operational controls are properly designed and working. It does not certify compliance with GDPR, CCPA, or any other privacy law, and that gap is worth sitting with because it's easy to blur the two together. A vendor can hold SOC 2 Type II, even pair it with ISO 27001, and still run afoul of GDPR, for instance by lacking a documented legitimate interest basis for processing B2B contact data. The frameworks are answering different questions entirely.

For a gifting platform, this isn't theoretical. These platforms routinely collect and process personal data belonging to California residents and EEA residents as a normal part of the workflow: recipient addresses, email addresses, stated gift preferences. All of that sits squarely inside GDPR and CCPA territory.

This is where the controller/processor distinction from earlier stops being an abstract legal concept and starts mattering in a very concrete way. The buying company, as controller, stays legally responsible for how recipient data gets processed, even though the platform, as processor, is the one actually handling it day to day. That's exactly why a Data Processing Agreement is a separate document from the SOC 2 report, not a redundant one. SOC 2's Privacy criterion checks whether a vendor has controls around collecting, using, retaining, and disposing of PII. GDPR asks for more: a documented lawful basis for processing, real consent mechanisms, breach notification timelines, and a working process for handling data subject rights requests, like someone asking to have their information deleted for good.

Procurement's job here is to request both documents and treat them as complementary, never as substitutes for each other. For any gifting program operating globally, shipping to well over a hundred countries, the privacy picture stretches wider than GDPR and CCPA alone. Legal teams should confirm which jurisdictions a vendor's privacy program actually covers, rather than assuming coverage under one or two major frameworks extends everywhere else by default.

The specific questions to ask a gifting vendor before signing a contract

Given everything above, a procurement or IT team walking into a vendor conversation should show up with a short, pointed list, not a general "are you secure" question that invites a general, useless answer back.

Ask whether the vendor holds a SOC 2 report, and if so, whether it's Type I or Type II, along with the exact observation period the current report covers. Ask which of the five Trust Services Criteria are in scope, since Security alone leaves Processing Integrity and Privacy, arguably the two most relevant criteria for this category, completely unaddressed. Ask for the report itself, not a summary or a badge sitting on a homepage. Ask whether the vendor will sign a Data Processing Agreement, and whether that DPA addresses GDPR and CCPA by name or leaves the client to sort out jurisdictional gaps on its own. For any program operating across multiple countries, ask which additional privacy regimes the vendor's program has actually been built to handle.

None of this requires a legal background to ask. It requires knowing that "SOC 2 compliant" is a phrase that can mean five very different things depending on report type and scope, and that the gap between those meanings is exactly what separates a vendor ready for enterprise data from one that's borrowed the vocabulary without doing the underlying work.

Sources

  1. Security and Ease a Priority, Giftbit Completes SOC 2 Compliance
  2. SOC 2 Compliance Requirements
  3. Why SOC 2 Is Essential For Your Rewards Program Partner
  4. perkupapp.com

More in Gifting Automation & Tools