generated: '2026-07-14' method: searched probe: false source: https://docs.stripe.com/security url: https://docs.stripe.com/security description: >- Stripe's security & compliance posture, captured from docs.stripe.com/security. Stripe is a PCI Service Provider Level 1 (the most stringent level in the payments industry). SOC 1/SOC 2 Type II reports are produced annually and provided on request; a public SOC 3 report is available. The automated trust-center probe did not record this because Stripe exposes compliance via its docs security page and Dashboard rather than a trust. subdomain with the probe's keyword threshold — this is the searched, human-verified fill. certifications: - {name: PCI DSS, level: Service Provider Level 1, note: Most stringent level of certification in the payments industry.} - {name: SOC 1 Type II, availability: on request, cadence: annual} - {name: SOC 2 Type II, availability: on request, cadence: annual} - {name: SOC 3, availability: public report} - {name: EMVCo Level 1 and 2, scope: Stripe Terminal card readers} - {name: PCI PA-DSS, scope: Stripe Terminal} - {name: NIST Cybersecurity Framework, note: Security policies aligned to the framework.} - {name: APEC CBPR and PRP, scope: cross-border privacy} - {name: EU-US Data Privacy Framework, note: Includes UK Extension and Swiss-US DPF.} report_access: soc_reports: Provided upon request; SOC 3 is a public report linked from the security page. dashboard: Compliance documents available to account holders via the Stripe Dashboard. docs: - https://docs.stripe.com/security - https://docs.stripe.com/security/guide evidence: - {source: https://docs.stripe.com/security, keywords: [pci service provider level 1, soc 1 type ii, soc 2 type ii, soc 3, emvco, nist]}