Maslow Insights

Most AI vendors are still writing their first SOC 2.

We’ve been
doing this
for over 25 years.

Maslow runs on the same enterprise infrastructure that’s carried Fortune 500 recognition programs for over 25 years. Tenant isolation, role-based access, a read-only AI, sensitive fields hidden by default, and SOC 2 Type II, all documented and ready before your security team even asks.

The Four Answers

Four Questions,
Four Straight Answers.

Every enterprise security team asks the same four questions before a pilot gets signed. Here they are, answered plainly.

01

Architecture: Data Isolation

Every client’s data is walled off inside RewardStation®, encrypted in transit (TLS 1.2+) and at rest (AES-256). Maslow only ever queries the tenant it’s working in and never anyone else’s.

Company-wide benchmarks (the kind behind a stat like “recognized employees retain at 2.5x”) come from aggregated patterns across our 25+-year dataset, not from looking into your tenant. Your data doesn’t leave your boundary, by design.

Tenant IsolationTLS 1.2+AES-256 at RestNo Cross-Tenant Joins

02

Authentication: Identity & Access

Sign in through your existing RewardStation® identity provider (SAML 2.0 or OIDC). Permissions follow your org chart automatically: a regional manager sees their region, a CHRO sees everything, and nobody sees more than their role allows.

SCIM provisioning keeps user access in sync with your HR system, so it’s never a second thing to manage. Every admin action gets logged automatically.

SAML 2.0OIDCSCIM ProvisioningRole-based Access

03

AI Behavior: AI Governance

Maslow reads and recommends. It doesn’t change your program, send messages, or touch settings. Only a human admin can do that through the normal interface. The AI is advisory, not in charge.

Sensitive fields like compensation, protected demographics, and PII-containing comments are hidden from the AI before it ever sees them. Your data is never used to train shared models, full stop.

Read-only AIField SuppressionNo Shared TrainingHuman-in-the-loop

04

Compliance: Audit & Compliance

We’re SOC 2 Type II certified, and we’ll get your security team the audit report within 48 hours of asking.

SOC 2 Type II

Procurement Q&A

The Questions Your
Team Will Ask.

The questions enterprise security teams ask first, answered in plain language.

Where is the data hosted?

RewardStation® runs on enterprise-grade cloud infrastructure in the USA.

What encryption standards are used?

TLS 1.2+ in transit, AES-256 at rest, with key management and rotation through an enterprise-grade KMS.

Is customer data used to train AI models?

No. Customer data is never used to train shared models. Maslow draws on a separate, curated benchmark dataset for cross-client patterns; your analysis runs only against your own tenant.

What can the AI actually do?

It’s read-only. Maslow doesn’t change settings, send messages, or modify permissions, any change to your platform requires a human administrator.

How are sensitive fields handled?

Compensation, protected demographics, and PII-containing text are suppressed before the AI ever sees them. Suppression rules are configurable per client.

How are admin actions logged?

Every admin action, including user creation, permission change, and AI queries are logged with who, when, and what.

What’s the incident response posture?

Documented response procedures aligned to SOC 2, with notification timelines in the master agreement. Full documentation is available under NDA.

What about certifications beyond SOC 2 Type II?

ISO 27001 and HIPAA are common requests, and regional frameworks like GDPR data processing addendums are standard for our enterprise clients. Roadmap available under NDA.

Certifications & Standards

Documented, Audited,
and
Already in
Your Inbox.

A member of a client's security team reviewing documentation at her desk
  • SOC 2 Type II
  • SSO / SAML 2.0
  • SCIM Provisioning
  • AES-256 at Rest
  • TLS 1.2+ in Transit
  • Read-Only AI
  • Field-Level Suppression

Bring Your Security Team
to the First Call Ready.

Request the SOC 2 Type II report, the security architecture overview, and the standard data processing addendum under NDA. We turn around documentation within 48 hours of request, so your security review starts on common ground rather than catching up.