generated: '2026-09-18' method: searched source: https://www.trustly.com/security sources: - https://www.trustly.com/security - https://amer.developers.trustly.com/.well-known/api-catalog - https://amer.developers.trustly.com/integrate/core-concepts/key-concepts - openapi/trustly-north-america-openapi.yml - https://docs.trustly.com/api/api-protocol conformance: - id: iso-27001 conforms: true kind: certification evidence: https://www.trustly.com/security ("Trustly is ISO 27001-certified and servers are hosted at ISO 27001-certified facilities") - id: gdpr conforms: true kind: regulation evidence: https://www.trustly.com/security ("GDPR-compliant") - id: psd2 conforms: true kind: regulation evidence: https://www.trustly.com/security — Trustly Group AB is a licensed Swedish payment institution operating under the Swedish Payment Services Act (2010:751) and Directive (EU) 2015/2366 (PSD2), supervised by Finansinspektionen note: PSD2 here is the licensing regime for the provider; Trustly is a payment initiation service, not an ASPSP publishing a PSD2/Berlin-Group/OBIE API - id: uk-psr-2017 conforms: true kind: regulation evidence: https://www.trustly.com/security — Trustly UK Limited is an FCA-authorised payment institution (FRN 1005703) - id: nacha conforms: true kind: scheme rules evidence: https://amer.developers.trustly.com/integrate/core-concepts/key-concepts — the Lightbox authorization includes the NACHA agreement; ACH returns use the standard R01–R84 codes (status-codes page) - id: rfc9727-api-catalog conforms: true kind: rfc evidence: https://amer.developers.trustly.com/.well-known/api-catalog served as application/linkset+json with the RFC 9727 profile, naming the OpenAPI as service-desc (saved as well-known/trustly-api-catalog.json) - id: openapi-3.1 conforms: true kind: specification evidence: https://amer.developers.trustly.com/openapi.json (openapi 3.1.0, 29 paths, 31 operations, 10 webhooks, 159 schemas) - id: json-rpc-1.1 conforms: true kind: specification evidence: https://docs.trustly.com/api/api-protocol — the Europe API implements JSON-RPC 1.1 with RSA-signed requests - id: mcp conforms: true kind: protocol evidence: https://amer.developers.trustly.com/_mcp/server — initialize returned protocolVersion 2025-06-18 (docs-search server only) - id: llms-txt conforms: true kind: convention evidence: https://amer.developers.trustly.com/llms.txt (200, text/plain; docs.trustly.com/llms.txt is 404) - id: oauth2 conforms: false evidence: no OAuth 2.0 authorization server, scopes or discovery metadata on any host; the "OAuth" in the docs is the bank-side login the consumer completes inside the Lightbox - id: oidc conforms: false evidence: /.well-known/openid-configuration 404 on every host probed - id: rfc9457 conforms: false evidence: errors are {"errors":[{"domain","code","message","occurredAt"}]} with numeric codes, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on www.trustly.com, trustly.one, api.trustly.com, amer.developers.trustly.com and docs.trustly.com; disclosure is a web page (https://www.trustly.com/security/disclosure) instead - id: idempotency-key conforms: false evidence: replay protection is by unique merchantReference on establish/capture/deposit (code 210 on duplicates), not an Idempotency-Key header; see conventions/trustly-conventions.yml - id: pci-dss conforms: null evidence: not claimed on https://www.trustly.com/security; Pay by Bank flows carry no card data - id: soc2 conforms: null evidence: not claimed on https://www.trustly.com/security - id: fdx conforms: null evidence: no FDX data-sharing API is published; account data is returned in Trustly's own schemas (AccountSummary, Balance, User) domain_standard_signature: found: false note: >- Checked the contract for a declared domain standard: no ISO 20022 message types, no NACHA file formats, no FDX or Berlin Group / OBIE shapes, no Open Banking consent model appear in the OpenAPI. The North America API is a proprietary REST projection over ACH/RTP/FedNow rails; the Europe API is a proprietary JSON-RPC surface. Reward-only check, so nothing is asserted.