generated: '2026-07-19' method: searched source: >- Feedzai published compliance claims (feedzai.com/legal/ethical-ai-policy, /legal/data-processing-agreement, /legal/feedzai-vendor-compliance-guide) and the RFC 9116 security.txt at feedzai.com/.well-known/security.txt. Feedzai's product APIs are enterprise/NDA-gated so no OpenAPI is available to derive protocol-level conformance; the standards below are the published organizational security & regulatory posture of a financial-crime prevention platform processing card and payment data. standards: - id: iso-27001 conforms: true evidence: >- Feedzai holds ISO/IEC 27001 certification (Information Security Management System), stated on the AI Policy and Data Processing Agreement pages. - id: pci-dss conforms: true evidence: >- Feedzai is PCI DSS Level 1 certified (handles cardholder / payment data as a risk-scoring service provider). - id: soc2-type-ii conforms: true evidence: >- Feedzai produces a SOC 2 (Type II) report, referenced in the Data Processing Agreement and vendor compliance materials. - id: gdpr conforms: true evidence: >- Feedzai's Data Processing Agreement and Privacy Notice commit to GDPR compliance; the platform is deployed for EU financial institutions. - id: eu-ai-act conforms: partial evidence: >- Feedzai's Ethical AI Policy states alignment with the forthcoming EU AI Act and the CISA/NCSC "Guidelines for secure AI system development". - id: rfc9116-security-txt conforms: true evidence: >- feedzai.com/.well-known/security.txt publishes Contact, Encryption, Canonical and Preferred-Languages fields.