Vendor
Stripe
stripe.com
Stripe is a financial services platform that helps all types of businesses accept payments, build flexible billing models, and manage money movement.
Pricing model: unknown
Last change: Sep 19, 2026
Observed customers
First seen Sep 19, 2026 · United States · Subprocessor
First seen Sep 19, 2026 · Subprocessor
Disclosed vendors
Disclosed vendors
First seen Sep 19, 2026 · Stripe maintains and enforces a security program that addresses how Stripe manages security, including its security controls. The security program includes: - documented policies that Stripe formally approves, internally publishes, communicates to appropriate personnel and reviews at least annually; - documented, clear assignment of responsibility and authority for security program activities; - policies covering, as applicable, acceptable computer use, data classification, cryptographic control · Subprocessor
First seen Sep 19, 2026 · Stripe performs risk assessments, and implements and maintains controls for risk identification, analysis, monitoring, reporting and corrective action.Stripe maintains and enforces an asset management program that appropriately classifies and controls hardware and software assets throughout their life cycle. · Subprocessor
First seen Sep 19, 2026 · All (a) Stripe employees; and (b) Stripe independent contractors who may have access to data, including those who Process Personal Data ((a) and (b), collectively ‘‘Personnel”) acknowledge their data security and privacy responsibilities under Stripe’s policies.For Personnel, Stripe, either itself or through a third party: - implements pre-employment background checks and screening; - conducts security and privacy training; - implements disciplinary processes for violations of data security or p · Subprocessor
First seen Sep 19, 2026 · Annual Security and Privacy Training. Stripe’s employees complete an annual Security and Privacy awareness training on Stripe’s data security and confidentiality policies and practices. · Subprocessor
First seen Sep 19, 2026 · Policies and Procedures. Stripe implements policies and procedures for network and operations management. These policies and procedures address hardening, change control, segregation of duties, separation of development and production environments, technical architecture management, network security, malware protection, protection of data in transit and at rest, data integrity, encryption, audit logs and network segregation.Vulnerability Assessments. Stripe performs periodic vulnerability assess · Subprocessor
First seen Sep 19, 2026 · Access control. Stripe implements measures to prevent data processing systems from being used by unauthorized persons, including the following measures:- user identification and authentication procedures; - ID/password security procedures, including stronger digital authentication measures based on NIST 800-63B including MFA;- automatic blocking (e.g., password or timeout); and- break-in-attempt monitoring. Data access control. Stripe implements measures to ensure that persons entitled to use a · Subprocessor
First seen Sep 19, 2026 · Stripe uses reputable third-party service providers to host its production infrastructure. Stripe relies on these third parties to manage the physical access controls to the data center facilities that they manage. Some of the measures that Stripe’s service providers provide to prevent unauthorized persons from gaining physical access to the data processing systems available at premises and facilities (including databases, application servers and related hardware), where Personal Data is Process · Subprocessor
First seen Sep 19, 2026 · Stripe implements measures to ensure the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident, including:- database replication;- backup procedures;- hardware redundancy; and- a disaster recovery plan. · Subprocessor
First seen Sep 19, 2026 · Stripe implements measures to ensure that Personal Data (a) cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic); and (b) can be verified to which companies or other legal entities Personal Data are disclosed, including logging, transport security and encryption. · Subprocessor
First seen Sep 19, 2026 · Stripe implements measures to monitor whether data have been entered, changed or removed (deleted), and by whom, from data processing systems, including logging and reporting systems, and audit trails and documentation. · Subprocessor
First seen Sep 19, 2026 · Stripe implements measures to ensure that Personal Data collected for different purposes can be Processed separately, including:- “least privilege” limitation of access to data by internal services;- segregation of functions (production/testing);- procedures for storage, amendment, deletion, transmission of data for different purposes; and- logical segmentation processes to manage the separation of Personal Data. · Subprocessor
First seen Sep 19, 2026 · PCI Compliance. To the extent applicable to the Services, Stripe is responsible for providing the Services in a manner that is consistent with the highest certification level (PCI Level 1) provided by the PCI-DSS requirements. Stripe’s certification is confirmed annually by a qualified security assessor (QSA).SOC Reports. Stripe maintains Service Organization Controls (“SOC”) auditing standards for service organizations issued under the AICPA. SOC 1 and 2 reports are produced annually and will b · Subprocessor
Recent changes
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Vendor Added
Date pending
Baseline
Dpa
Date pending