Executive Summary
AI-generated analysis for Razorpay
Razorpay (razorpay.com), operating as RAZORPAY SOFTWARE LIMITED (LEI: 335800MPTXBI8YNP7245, registered in India), has been assessed as a Tier 4 (Low Risk) vendor with a confidence score of 72%. Razorpay is a prominent Indian payment infrastructure platform, and this assessment reflects a broadly clean risk profile across technical, reputational, and sanctions dimensions. Several positive signals support the low-risk determination:
Key Findings
- Razorpay is an active, formally registered legal entity with a verified LEI in good standing.
- No sanctions matches were identified across OFAC, EU, UN, and other major watchlists.
- Domain reputation is clean across SURBL, Spamhaus DBL, URLhaus, and Malware detection service, with zero abuse reports on the primary CDN IP.
- Infrastructure exposure is minimal: only 2 open ports (80 and 443) are exposed, zero known CVEs are associated with the infrastructure, and the domain is served via Cloudflare CDN — representing a well-controlled footprint significantly below the SaaS industry average of 8–12 open ports.
- The vendor explicitly commits to not training AI models on customer data, discloses third-party AI providers (OpenAI and Anthropic), and claims a zero-retention posture for AI-processed data — all positive signals for data-sensitive buyers.
- No adverse media was found in historical or recent searches, and Hacker News community discussion shows no risk signals. Two areas warrant attention before or shortly after onboarding:
- The subprocessor page at trust.razorpay.com/subprocessors exists but appears to contain placeholder content, with no individual subprocessors enumerable. For a payment platform handling medium-level data access, a complete GDPR Article 28-compliant subprocessor list is a material due diligence requirement.
- No compliance certifications (SOC 2, ISO 27001, PCI DSS, HITRUST, or FedRAMP) were identified through trust page scanning or independent public registry verification. Given that Razorpay is a payment infrastructure vendor, PCI DSS certification is a particularly important signal that buyers should verify directly. The HTTP security grade of C+ on the marketing site (razorpay.com) also suggests some header configuration gaps, though the application dashboard may be separately hardened. Overall, Razorpay presents as a low-risk vendor with a clean external profile and strong AI data handling commitments. The primary gaps — incomplete subprocessor disclosure and unverifiable compliance certifications — are addressable through direct engagement with the vendor's security team and do not in themselves elevate the risk tier.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation or input.