Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Expensify, your compliance team needs documented proof they can be trusted. ThirdProof investigated Expensify across 27 intelligence sources — here's what we found.
24 sources queried. 83% confidence. Every Expensify investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Expensify's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 31% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
No evidence from expensify.com sources confirms ISO 27001 certification; search results reference other companies' certifications but not Expensify's.
Q41
Not found in FedRAMP marketplace
Q42
Expensify's help documentation explicitly states 'Expensify is fully committed to meeting the requirements of the General Data Protection Regulation (GDPR)'.
Q39
Expensify's help documentation states 'Expensify follows the highest standard of security, known as the Payment Card Industry Data Security Standard' and external source confirms 'PCI DSS Level 1 certification'.
+ 3 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Expensify's Full Report Free →Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
24
Sources Queried
21
Sources With Data
March 25, 2026
Last Assessed
AI-generated analysis for Expensify
Expensify (expensify.com) is a spend management and expense reporting platform assessed at Risk Tier 3 (Moderate Risk), reflecting a vendor with a solid operational foundation but several transparency and configuration gaps that warrant attention before onboarding at medium data access levels.
Expensify presents a number of positive signals: the domain has been established for over 18 years with registration secured through 2035, and all active threat intelligence sources return clean results. The domain is free of malware blacklist entries (SURBL, Spamhaus DBL), Malware detection service returns no threats, and IP abuse scoring is clean with a 0% confidence score. The vendor's infrastructure is protected by Cloudflare CDN, and no known CVEs were identified against the exposed endpoints. TLS is configured with TLSv1.3 and a strong AES-256-GCM cipher suite. SOC 2 compliance is claimed on the vendor's trust page (https://help.expensify.com/articles/Unlisted/Compliance-Documentation), representing a positive signal, though independent verification is not publicly available. No sanctions matches, adverse media, or regulatory enforcement actions were identified. Several gaps require follow-up before full approval. The most operationally significant concern is the published subprocessor page (https://trust.expensify.com/subprocessors), which was found to contain placeholder content with no identifiable subprocessors — for a vendor with medium data access, a complete GDPR Article 28-compliant subprocessor list is a material due diligence requirement. Additionally, the public-facing website (expensify.com) received an F grade from Mozilla HTTP Observatory, with missing Content-Security-Policy and X-Frame-Options headers; while this applies to the marketing site rather than the application endpoint, it is a noteworthy configuration gap. No publicly accessible AI data usage policy was identified, which is a transparency gap given the increasing prevalence of AI features in expense management platforms. SOC 2 remains vendor-attested and unverified, and ISO 27001 certification was not found in public registries. Overall, Expensify is a long-established vendor with no active threat indicators or sanctions exposure, but unresolved transparency gaps — particularly around subprocessor disclosure and AI data handling — mean a conditional approval posture is warranted pending resolution of the items outlined below.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, and open-source intelligence tools without vendor participation or notification.
4 findings identified for Expensify
expensify.com received a failing grade (F) from Mozilla HTTP Observatory. This indicates serious HTTP security configuration issues. Note: This scan was performed on the marketing site (expensify.com). The application endpoint (app.expensify.com) may have different security headers. Verify the application domain separately.
A critical data source was unavailable during this investigation. Manual verification is recommended.
expensify.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
An AI-specific data usage policy was not discoverable for expensify.com through automated scanning of common policy paths and web search. The vendor may publish relevant data handling commitments in enterprise agreement documents (DPAs, product terms, licensing portals) that are not indexed at standard public URLs. Request the vendor's Data Protection Addendum or AI-specific terms directly.
21 positive signals verified
No LEI Registry Match (Expected for Most Companies)
Business Registration →No Sanctions Matches Found
Sanctions & Watchlist Screening →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →9 Open Ports Detected
Infrastructure Exposure →Established Domain (18+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Minimal Tech Community Discussion
Tech Community Sentiment →Certificate Data from TLS Handshake
Certificate Transparency →Web Archive History Unavailable
Web Archive History →No Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Certification Claimed: CCPA (Inherited)
Trust & Compliance Page Scan →Subprocessor Page Found (Placeholder)
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →News Coverage Found (No Risk Signals)
Historical Media Search →HITRUST Directory Match — Manual Verification Required
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Steps to address findings for Expensify
Request the SOC 2 Type II report and bridge letter: Contact Expensify's security team directly or visit https://help.expensify.com/articles/Unlisted/Compliance-Documentation to request a current report. Ask for a bridge letter if the report period ended more than 6 months ago. Store in your vendor risk register with a 12-month renewal reminder.
Obtain a complete subprocessor list before finalizing onboarding: Email Expensify's legal or privacy team requesting the current GDPR Article 28 subprocessor list, including infrastructure providers and any third-party services that receive customer financial data. Set a 10-business-day deadline. If no response, escalate to conditional hold.
Clarify AI data handling practices in writing: Ask Expensify whether AI features process customer data, which third-party model providers are used, whether customer data is used for training, and whether an opt-out is available. Request this in writing as part of a DPA or AI addendum within 15 business days.
Verify security headers on the application endpoint: Independently check app.expensify.com using HTTP security scanner (https://observatory.mozilla.org/analyze/app.expensify.com). If the application domain also lacks CSP and X-Frame-Options, request a written remediation timeline from the vendor's security team.
Confirm TLS certificate renewal process: Ask the vendor's security team whether certificate renewal is automated. If manual, request confirmation that renewal is scheduled before the 60-day mark (approximately April 20, 2026 based on the June 20, 2026 expiry).
Conduct manual adverse media review: Search Google News and LexisNexis for 'Expensify' filtered to the past 12–24 months to check for data breaches, regulatory actions, executive changes, or financial instability, as the automated adverse media scan was unavailable during this assessment.
24 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Expensify? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Expensify on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Expensify's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Expensify a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Expensify appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Expensify's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Expensify's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Expensify claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Expensify depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Expensify appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Expensify (NASDAQ: EXFY) provides enterprise expense management including corporate card programs, receipt scanning, expense report workflows, and employee reimbursements. This means Expensify accesses corporate card numbers, bank account details, and sensitive employee financial information — making SOC 2 and PCI DSS compliance critical. Expensify claims SOC 2 Type II certification and maintains PCI DSS compliance for card data handling. ThirdProof's assessment independently assesses these claims and verifies Expensify's security posture across the full vendor surface area.
ThirdProof investigated Expensify across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 90% confidence. Sanctions screening returned clear with no OFAC, EU, or UN matches. Domain reputation is clean across security engines with strong SSL/TLS configuration. No adverse media, enforcement actions, or malware indicators were detected in the assessment period. Expensify's public company status (NASDAQ: EXFY) provides additional transparency through SEC filings and annual audit requirements.
Organizations evaluating Expensify should consider: (1) PCI DSS scope — determine whether Expensify stores cardholder data directly or uses tokenization, (2) SOC 2 trust service criteria coverage for expense data processing and storage, (3) data retention policies for receipts, bank account details, and reimbursement records, and (4) integration security for bank feeds and accounting system connections that may create additional data flow paths. ThirdProof's assessment covers these dimensions in a single automated assessment.
Your first 5 Expensify assessments are free — no credit card, no vendor participation required. ThirdProof queries 27 intelligence sources autonomously: OFAC SDN screening, SOC 2 verification, PCI DSS compliance, business registration, adverse media analysis, cyber risk scoring, and more. Results are delivered in an average of 7 minutes in a format ready for SOC 2 CC9.2 and PCI DSS 12.8 compliance evidence packages.
Seeing this in an audit? ThirdProof lets you investigate Expensify and every other vendor in your stack — average report time: 7 minutes. Get Expensify's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Expensify across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.