Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with PayPal, your compliance team needs documented proof they can be trusted. ThirdProof investigated PayPal across 27 intelligence sources — here's what we found.
27 sources queried. 100% confidence. Every PayPal investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get PayPal's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 62% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
PayPal's trust center lists ISO/IEC 27001 as a compliance certification with access available to customers.
Q41
Not found in FedRAMP marketplace
Q40
PayPal does not sign BAAs and does not offer HIPAA compliance; they only support payment processing with a HIPAA payment processing exemption if PHI is kept out of the platform.
Q42
PayPal is GDPR compliant and has a Data Protection Addendum (DPA) available; they rely on Binding Corporate Rules and other data transfer mechanisms for GDPR compliance.
+ 9 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get PayPal's Full Report Free →Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
26
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for PayPal
PayPal (paypal.com) is a globally recognized payment processing platform assessed at Risk Tier 3 (Moderate Risk), reflecting a combination of strong foundational security controls and a series of confirmed security incidents and active legal proceedings that require careful attention from procurement and risk teams. On the positive side, PayPal demonstrates several mature security practices:
Independence Statement
All evidence in this assessment was independently sourced from external registries, threat intelligence databases, public media, and automated web scans without vendor participation or input.
6 findings identified for PayPal
3 recent article(s) reference critical security or regulatory issues for "PayPal": "PayPal Data Breach Confirmed—Money Was Stolen, Passwords Now Reset" (Forbes) https://news.google.com/rss/articles/CBMisAFBVV95cUxPZ1ZlUFlUQWxoWUZja2t4azF2TndzcWxzNGRYYjRQY19XcG5hUzR4bUxINVUwaThPWmxqSWZMTld2d0ZIeU1oNzdyUUM1TWJsTV9iUDFJaWplUzM5OW1JdXFOQXJYLVN6YnloeUhyaHVjckNUY1cySU5PZFV5c3pwdEpnZExzckUwZ2VkQTZ4b0xEYzFhci02LXpJR2F1MHNWWkt5a3RMWU1RaGdVRHVpNw?oc=5; "PayPal says cyber incident left Social Security numbers exposed for months" (Cybernews) https://news.google.com/rss/articles/CBMihgFBVV95cUxPdUhONS1wNHk4Qk5NZlRIS3JQb0llcEtLd0ZNYm54TEhFdmhCLXY3aWdTSFFzRHJtLWlaRy1Vc0ZGTWYwYk54eTI1Um9TZ0lZM2lZMGpsV2syUllHaUE2S09TT3hUM1RrLTJvQ1hpbzBYS3B2aVBVdG8tQlFxTldiUTNMcmtpQQ?oc=5; "PayPal Breach, Chrome 0-Day, BeyondTrust RCE Exploit, and More" (CyberSecurityNews) https://news.google.com/rss/articles/CBMiZ0FVX3lxTE5neUVxRVBDckFJLV9TUGpHUEJFSkZEeVFlaTlwbWVnN2w5bHhNZ2M4eGZnUFQzaWRMZ0xQT2tTdnN5WXNrVm5iSjZDYk9HQ2U5empiNzVVVHVvbUVYd29HdHkzOUZFOEk?oc=5
Article from securityboulevard.com: "What the Recent PayPal Breach Says About Modern Web Risk - Security Boulevard"
Article from allaboutlawyer.com: "PayPal Class Action Lawsuits 2026: Which One Affects You?"
Article from nationaltoday.com: "Investors Seek Lead Plaintiff Role in PayPal Class Action Lawsuit - San Diego Today"
paypal.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
paypal.com has certificates from 21 different Certificate Authorities. This may indicate inconsistent certificate management practices.
25 positive signals verified
Legal Entity Actively Registered
Business Registration →Sanctions Data Incomplete
Sanctions & Watchlist Screening →Low-Confidence Sanctions Matches Only
Sanctions & Watchlist Screening →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (26+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: security incident
Tech Community Sentiment →Tech Community Discussion: security
Tech Community Sentiment →Tech Community Discussion: operational
Tech Community Sentiment →HTTP Security Grade: A+
HTTP Security Scan →Large Certificate Footprint (2072 subdomains)
Certificate Transparency →Established Web Presence (26+ years)
Web Archive History →Domain in 50 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Trust Page Found, No Certifications Detected
Trust & Compliance Page Scan →4 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for PayPal
Request PayPal's current SOC 2 Type II report and bridge letter directly from your PayPal account manager or compliance contact — check https://www.paypal.com/us/compliancereports/faqs first, as PayPal's compliance page may have a request mechanism. Ask for a report dated within the last 12 months and confirm it covers the specific PayPal services in scope for your integration.
Request a written statement from PayPal's legal or compliance team on the status of the three active 2026 class action lawsuits and any ongoing obligations from the January 2025 NYDFS $2M cybersecurity fine — specifically, whether remediation commitments from the NYDFS consent order are complete and what controls were implemented post-incident.
Review PayPal's Data Processing Addendum (https://www.paypal.com/us/legalhub/paypal/dpa-business-management) and ensure your organization has executed a current version. Confirm contractual provisions for breach notification timelines, as PayPal's DPA commits to 'written notice without undue delay' — negotiate a specific timeframe (e.g., 72 hours) if your regulatory obligations require it.
Ask PayPal's security team directly whether customer data processed through your integration is used to train AI or ML models, and whether an enterprise opt-out is available — reference the [privacy policy](https://www.paypal.com/us/legalhub/paypal/privacy-full) as a starting point but request a written supplementary statement, as the current policy does not clearly address AI training commitments.
Monitor the PayPal domain SSL certificate expiry (July 7, 2026) by setting an internal calendar alert for June 1, 2026 — verify at that time using the [SSL/TLS analysis service analyzer](https://www.SSL/TLS analysis service.com/ssltest/analyze.html?d=paypal.com) that renewal has occurred. If your integration depends on specific PayPal subdomains, verify their certificate status separately.
Confirm whether PayPal holds PCI DSS certification applicable to your specific integration type by contacting your PayPal account manager — the Visa Merchant Agent list and Mastercard SDP registry were checked and returned no match, but PayPal's PCI compliance status may be maintained under a different entity name or program level not captured in public registries.
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you PayPal? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is PayPal on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is PayPal's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is PayPal a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has PayPal appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is PayPal's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are PayPal's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does PayPal claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does PayPal depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has PayPal appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
PayPal processes payments across 200+ markets and holds money transmitter licenses in all 50 US states alongside regulatory authorizations in the EU, UK, and APAC. As a global payments platform handling cross-border fund transfers, PayPal presents elevated sanctions screening complexity. Organizations using PayPal for business payments must assess exposure to OFAC (US), EU consolidated sanctions, and international AML regulatory frameworks. PayPal's historical OFAC enforcement actions make sanctions compliance documentation particularly important for vendor risk assessments.
ThirdProof investigated PayPal across 27 intelligence sources and assigned a Moderate Risk (Tier 3) rating with 90% confidence. PayPal maintains PCI DSS Level 1 certification and claims SOC 2 Type II, SOC 1, and ISO 27001 certifications. Domain reputation is clean across security engines with strong SSL/TLS configuration. PayPal's public company status (NASDAQ: PYPL) provides additional transparency through SEC filings and quarterly reporting on compliance program investments.
Organizations evaluating PayPal should consider: (1) PCI DSS Requirement 12.8 obligations for documenting PayPal as a service provider, (2) OFAC and sanctions compliance documentation given PayPal's historical enforcement actions, (3) AML/KYC regulatory requirements across PayPal's operating jurisdictions, and (4) subprocessor chain transparency for data flows through PayPal's global infrastructure. ThirdProof's assessment covers all of these dimensions in a single automated assessment.
Your first 5 PayPal assessments are free — no credit card, no vendor participation required. ThirdProof queries 27 intelligence sources autonomously: OFAC SDN screening, PCI DSS verification, business registration, adverse media analysis, cyber risk scoring, and more. Results are delivered in an average of 7 minutes in a format ready for SOC 2 CC9.2, PCI DSS 12.8, and AML compliance evidence packages.
Seeing this in an audit? ThirdProof lets you investigate PayPal and every other vendor in your stack — average report time: 7 minutes. Get PayPal's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates PayPal across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.