Sample memo (illustrative public-SaaS profile). Live scans vary by what the vendor publishes.
Vendor Risk Memo: stripe.com
Financial infrastructure / payment processor · Decision support only, not a certification.
Executive summary
Stripe shows a mature public security posture for a global payments platform: SOC 2 Type II availability, PCI DSS Level 1, published DPA/GDPR statements, HackerOne disclosure, and a high historical uptime claim. Gaps are typical of public-only review (internal MFA, encryption-at-rest detail, AI training clause). Approve with conditions: obtain current SOC 2 + DPA AI clause before production card data.
Key findings
Public security pages state annual SOC 1 and SOC 2 Type II reports available on request.
security.txt points to HackerOne/stripe.
Confirm in the DPA that customer data is not used to train models.
What you do next
- Request current SOC 2 Type II + bridge letter
- Execute DPA with AI-training prohibition if required
- Record Approve with conditions in RiskMemo