Vendor

StripeStripe

stripe.com

Stripe is a financial services platform that helps all types of businesses accept payments, build flexible billing models, and manage money movement.

Pricing model: unknown

Last change: Sep 19, 2026

Observed customers

fly.iofly.io

First seen Sep 19, 2026 · United States · Subprocessor

huggingface.cohuggingface.co

First seen Sep 19, 2026 · Subprocessor

All observed customers →

Disclosed vendors

Disclosed vendors

Security Programs and PoliciesSecurity Programs and Policies

First seen Sep 19, 2026 · Stripe maintains and enforces a security program that addresses how Stripe manages security, including its security controls. The security program includes: - documented policies that Stripe formally approves, internally publishes, communicates to appropriate personnel and reviews at least annually; - documented, clear assignment of responsibility and authority for security program activities; - policies covering, as applicable, acceptable computer use, data classification, cryptographic control · Subprocessor

Risk and Asset ManagementRisk and Asset Management

First seen Sep 19, 2026 · Stripe performs risk assessments, and implements and maintains controls for risk identification, analysis, monitoring, reporting and corrective action.Stripe maintains and enforces an asset management program that appropriately classifies and controls hardware and software assets throughout their life cycle. · Subprocessor

Personnel Education and ControlsPersonnel Education and Controls

First seen Sep 19, 2026 · All (a) Stripe employees; and (b) Stripe independent contractors who may have access to data, including those who Process Personal Data ((a) and (b), collectively ‘‘Personnel”) acknowledge their data security and privacy responsibilities under Stripe’s policies.For Personnel, Stripe, either itself or through a third party: - implements pre-employment background checks and screening; - conducts security and privacy training; - implements disciplinary processes for violations of data security or p · Subprocessor

Training and AwarenessTraining and Awareness

First seen Sep 19, 2026 · Annual Security and Privacy Training. Stripe’s employees complete an annual Security and Privacy awareness training on Stripe’s data security and confidentiality policies and practices. · Subprocessor

Network and Operations ManagementNetwork and Operations Management

First seen Sep 19, 2026 · Policies and Procedures. Stripe implements policies and procedures for network and operations management. These policies and procedures address hardening, change control, segregation of duties, separation of development and production environments, technical architecture management, network security, malware protection, protection of data in transit and at rest, data integrity, encryption, audit logs and network segregation.Vulnerability Assessments. Stripe performs periodic vulnerability assess · Subprocessor

Technical Access ControlsTechnical Access Controls

First seen Sep 19, 2026 · Access control. Stripe implements measures to prevent data processing systems from being used by unauthorized persons, including the following measures:- user identification and authentication procedures; - ID/password security procedures, including stronger digital authentication measures based on NIST 800-63B including MFA;- automatic blocking (e.g., password or timeout); and- break-in-attempt monitoring. Data access control. Stripe implements measures to ensure that persons entitled to use a · Subprocessor

Physical access controlsPhysical access controls

First seen Sep 19, 2026 · Stripe uses reputable third-party service providers to host its production infrastructure. Stripe relies on these third parties to manage the physical access controls to the data center facilities that they manage. Some of the measures that Stripe’s service providers provide to prevent unauthorized persons from gaining physical access to the data processing systems available at premises and facilities (including databases, application servers and related hardware), where Personal Data is Process · Subprocessor

Availability ControlsAvailability Controls

First seen Sep 19, 2026 · Stripe implements measures to ensure the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident, including:- database replication;- backup procedures;- hardware redundancy; and- a disaster recovery plan. · Subprocessor

Disclosure ControlsDisclosure Controls

First seen Sep 19, 2026 · Stripe implements measures to ensure that Personal Data (a) cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic); and (b) can be verified to which companies or other legal entities Personal Data are disclosed, including logging, transport security and encryption. · Subprocessor

Entry ControlsEntry Controls

First seen Sep 19, 2026 · Stripe implements measures to monitor whether data have been entered, changed or removed (deleted), and by whom, from data processing systems, including logging and reporting systems, and audit trails and documentation. · Subprocessor

Separation ControlsSeparation Controls

First seen Sep 19, 2026 · Stripe implements measures to ensure that Personal Data collected for different purposes can be Processed separately, including:- “least privilege” limitation of access to data by internal services;- segregation of functions (production/testing);- procedures for storage, amendment, deletion, transmission of data for different purposes; and- logical segmentation processes to manage the separation of Personal Data. · Subprocessor

Certifications and ReportsCertifications and Reports

First seen Sep 19, 2026 · PCI Compliance. To the extent applicable to the Services, Stripe is responsible for providing the Services in a manner that is consistent with the highest certification level (PCI Level 1) provided by the PCI-DSS requirements. Stripe’s certification is confirmed annually by a qualified security assessor (QSA).SOC Reports. Stripe maintains Service Organization Controls (“SOC”) auditing standards for service organizations issued under the AICPA. SOC 1 and 2 reports are produced annually and will b · Subprocessor

All disclosed vendors →

Recent changes

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Vendor Added

Date pending

Baseline

Dpa

Date pending