generated: '2026-08-04' method: searched probe: true url: https://www.gofundme.com/c/security name: GoFundMe Security note: >- There is no dedicated trust-center subdomain (trust.gofundme.com and security.gofundme.com do not resolve; a trust-portal probe returned nothing). GoFundMe publishes its security and compliance posture as a single page on the main site, which is where the certifications below are named. certifications: - name: PCI DSS level: Level 1 Service Provider status: certified detail: >- Audited annually by an independent PCI Qualified Security Assessor; listed on the Visa Global Registry of Service Providers. Attestation of Compliance available on request. - name: NIST Cybersecurity Framework status: aligned detail: Program aligned to NIST CSF with controls drawn from NIST 800-53 and CIS CSC Top 20. - name: ISO 27001 status: inherited detail: Cited for the AWS hosting infrastructure, not held by GoFundMe itself. practices: encryption_in_transit: TLS 1.2+ with AES-256 encryption_at_rest: FIPS-approved AES-256 hosting: AWS sdlc: - Risk assessments based on the OWASP Top 10 - Static, dynamic and software composition analysis - Mandatory secure-coding training for developers bug_bounty: program: private platform: Bugcrowd paid: true detail: >- GoFundMe runs a private bug bounty with Bugcrowd. Researchers outside the program may still submit via the form on the security page. Accepted unknown findings are eligible for payment. Public disclosure of findings requires prior written approval. in_scope_domains: - gofundme.com - api.gofundme.com - funds.gofundme.com - gateway.gofundme.com external_references: - https://usa.visa.com/splisting/splistingindex.html - https://aws.amazon.com/security/ evidence: - source: https://www.gofundme.com/c/security keywords: [pci dss, level 1 service provider, nist cybersecurity framework, owasp top 10, bugcrowd, aws, iso 27001] fetched: '2026-08-04' http_status: 200 gaps: - No SOC 2 Type II report or attestation is named publicly. - No trust portal / compliance document request flow beyond "available upon request". - >- The compliance posture covers the consumer GoFundMe platform; nothing equivalent is published on the GoFundMe Pro developer surface for the API itself.