A cloud-native, API-first loyalty engine for enterprise commerce. Immutable ledger integrity, a governed DSL rules engine, GraphQL reporting with real-time subscriptions, and GDPR-by-design privacy — composable, headless, and priced well below Salesforce. Native warehouse sync is on the enterprise roadmap.
New to loyalty platforms? Read how it works →
Integrates with the enterprise commerce stack
Strip away the marketing and a loyalty programme is a simple promise: spend with us, and we'll owe you something back. Customers earn points, climb tiers, and redeem value — and every point you issue is a small financial liability your finance team owns, your auditors will test, and your customers notice the moment it's wrong.
That's why the hard part of loyalty isn't the front-end — it's the system of record underneath: a ledger that can't lose a point, rules you can change without a deploy, and privacy that survives both GDPR and an audit. VariaOS is that system of record, built so you don't have to build it.
New to loyalty platforms? Read the full primer — how it works, end to end →
One platform, three jobs made easier — from the team that designs the programme, to the engineers who wire it in, to the people who have to sign it off.
Design, launch, and govern a programme without a six-month build. The rules live in a governed DSL you control — not a backlog ticket.
One API-first engine, an immutable ledger you can trust, and GraphQL reporting that syncs straight to your warehouse.
Auditable by design, with GDPR right-to-erasure handled by cryptographic erasure — the ledger stays intact for the auditors.
Design, run, and govern loyalty programmes at scale — without owning the infrastructure or accepting the limitations of legacy platforms.
Append-only LedgerEntry model with atomic transaction grouping and snapshot-based balance queries. Financial-grade integrity — the platform cannot silently lose or double-count a point.
Human-readable DSL (ANTLR4) with a sandboxed evaluator, 50ms hard timeout, static complexity budget, dry-run simulation, and deterministic A/B traffic splitting — fully self-service.
Full GraphQL API with DataLoader, cursor pagination, real-time WebSocket subscriptions, and dataAsOf staleness metadata. GraphQL-first reporting in a market of REST-only APIs.
Planned: near-real-time Change Data Capture feeds to Snowflake, BigQuery, Azure Synapse/Fabric, and Redshift — DPA-gated with PII exclusion lists. Today, historical data moves in and out through the auditable order-data import API.
Per-customer AES-256 DEK/KEK envelope encryption, cryptographic erasure for right-to-erasure, and a PII-free event bus verified by negative tests in CI. Compliance as an engineering discipline.
CloudEvents v1.0, Transactional Outbox for at-least-once delivery, HMAC-signed webhook delivery with SSRF protection, and dead-letter queues with tiered alerting.
Earn and burn across any channel that can post an order — storefront, app, or POS middleware — through one idempotent API. Shopify and Salesforce OMS connectors in private beta; SFCC connector in private beta with cartridge certification in progress.
Built for environments where auditors ask hard questions: append-only transaction history, per-customer encryption, and an exportable, PII-redacted audit trail. No cardholder data touches the platform.
Model top-ups and plan upgrades as order events through the API, and let DSL rules on your own metadata award instantly — no code deploy. Recency and lifetime-value milestones are built into the rule language.
Miles-style earning with multi-tier ladders and automatic qualification, expiry managed lot-by-lot (first-expiring-first-out), and redemption as spendable credit through embeddable, themeable widgets. Reward catalogues and multi-region residency are on the roadmap.
Reward check-ins, milestones, and programme participation with auditable incentive flows — designed so clinical data never enters the loyalty layer: HMAC identities, a PII-free event bus, and cryptographic erasure keep the footprint minimal.
Automate performance-based reward issuance to distributors and channel partners. Configurable rule sets, real-time reporting, and traceable ledger history.
In a market of predominantly REST-only reporting, VariaOS ships a full GraphQL API with real-time subscriptions, DataLoader, and per-response staleness metadata.
Append-only, immutable LedgerEntry model with atomic transaction grouping and snapshot-based balance queries. Competitors operate on mutable balance fields or undisclosed architectures.
Planned: Snowflake, BigQuery, Azure Synapse/Fabric, and Redshift — native CDC with PII exclusion and DPA governance, where competitors route through third-party tools or scheduled exports. Historical data import is live today via the auditable import API.
A purpose-built cartridge for Salesforce Commerce Cloud with versioned field mapping templates and full OAuth 2.0 token lifecycle support — not a generic REST integration like every other platform. Cartridge certification is in progress.
Join the private beta, explore the API docs, or talk to us about design-partner and enterprise plans.