An Aeon AI Risk Management product

Sample memo (illustrative public-SaaS profile). Live scans vary by what the vendor publishes.

Vendor Risk Memo: stripe.com

Financial infrastructure / payment processor · Decision support only, not a certification.

APPROVE WITH CONDITIONS Score 48/100 8/20 controls verified from public sources

Executive summary

Stripe shows a mature public security posture for a global payments platform: SOC 2 Type II availability, PCI DSS Level 1, published DPA/GDPR statements, HackerOne disclosure, and a high historical uptime claim. Gaps are typical of public-only review (internal MFA, encryption-at-rest detail, AI training clause). Approve with conditions: obtain current SOC 2 + DPA AI clause before production card data.

Key findings

[POSITIVE] SOC 2 Type II

Public security pages state annual SOC 1 and SOC 2 Type II reports available on request.

[POSITIVE] Vulnerability disclosure

security.txt points to HackerOne/stripe.

[MEDIUM] AI training not explicit

Confirm in the DPA that customer data is not used to train models.

What you do next

  1. Request current SOC 2 Type II + bridge letter
  2. Execute DPA with AI-training prohibition if required
  3. Record Approve with conditions in RiskMemo
Run this on your vendor Scan stripe.com live