generated: '2026-08-04' method: searched source: https://payactiv.com/trust-center/ note: >- No OpenAPI is publicly reachable for Payactiv, so nothing here is derived from a specification. Every entry below is a claim Payactiv publishes on its own site, or an honest unknown. standards: - id: soc2 conforms: true evidence: 'SOC 2 badge and PCI/SOC/ISO control statement on https://payactiv.com/trust-center/' - id: iso-27001 conforms: true evidence: 'ISO 27001 Certified badge on https://payactiv.com/trust-center/' - id: pci-dss conforms: true evidence: >- PCI DSS badge on https://payactiv.com/trust-center/; external scans performed quarterly by a PCI Approved Scanning Vendor per https://payactiv.com/information-security-program/ - id: ccpa conforms: true evidence: >- CCPA badge on https://payactiv.com/trust-center/ and a CCPA-compliant Data Processing Agreement - id: visa-service-provider conforms: true evidence: 'Visa Service Provider badge on https://payactiv.com/trust-center/' - id: b-corp conforms: true evidence: 'Certified B Corporation / Public Benefit Corporation statement on the Trust Center' - id: nmls-registration conforms: true evidence: 'Payactiv, Inc. NMLS ID 2591928, plus state EWA licenses (WI, CT, NV)' - id: oauth2 conforms: unknown evidence: >- Not determinable anonymously. The developer portal gateway exposes /auth/login, /auth/signup and /auth/token/refresh endpoints for the portal itself; no product API auth scheme is published. - id: oidc conforms: unknown evidence: '/.well-known/openid-configuration is not served on any Payactiv host' - id: rfc9457-problem-details conforms: unknown evidence: 'No public OpenAPI or error reference to inspect' - id: hipaa conforms: false evidence: 'Not claimed on the Trust Center' - id: fedramp conforms: false evidence: 'Not claimed on the Trust Center'