generated: '2026-08-04' method: searched probe: true source: https://payactiv.com/trust-center/ url: https://payactiv.com/trust-center/ certifications: - SOC 2 - ISO 27001 - PCI DSS - CCPA - Visa Service Provider - Certified B Corporation programs: - name: Information Security Program url: https://payactiv.com/information-security-program/ summary: >- Policies, procedures and standards maintained in accordance with PCI/SOC/ISO controls. Publishes encryption at rest and in transit, mandatory multi-factor authentication, annual security training, employee background checks, an incident response plan with a reporting mechanism for suspected vulnerabilities, and log retention of 180 days minimum (one year for confidential data). - name: Data Processing Agreement url: https://payactiv.com/data-processing-agreement/ summary: California Consumer Privacy Act compliant data processing terms. - name: Privacy Policy url: https://payactiv.com/privacy-policy/ - name: Compliance Handbook url: https://www.payactiv.com/trust-center/compliance-handbook summary: EWA program compliance with state and federal wage-and-labor and consumer-protection law. testing: external_penetration_test: at least annually internal_penetration_test: twice yearly by an independent third party internal_vulnerability_scans: monthly minimum external_vulnerability_scans: quarterly minimum, via a PCI Approved Scanning Vendor remediation_sla: critical and high severity remediated within 30 days licensing: nmls_id: '2591928' ewa_licenses: - 'Wisconsin Department of Financial Institutions — EWA license 2591928EWA' - 'Connecticut Department of Banking — small loan license SLC-2591928' - 'Nevada Financial Institution Division — EWA license EWA00009' evidence: - source: https://payactiv.com/trust-center/ http_status: 200 keywords: [soc 2, iso 27001, pci dss, ccpa, visa service provider, trust center, b corporation] - source: https://payactiv.com/information-security-program/ http_status: 200 keywords: [pci, soc, iso, encryption, incident response, penetration test] notes: >- No public vulnerability disclosure policy, bug bounty program, or security@ contact was found. /.well-known/security.txt returns 404 on payactiv.com; the only published contact is the general support address, so no VulnerabilityDisclosure artifact or Security pointer was emitted.