Aeropay · Trust Center

Aeropay Trust Center

Trust center

Aeropay maintains a public trust center documenting SOC 2 and Nacha ACH Operating Rules compliance.

PaymentsPay by BankACHOpen BankingFintechBank linkingFinancial ServicesReal-Time PaymentsWebhookPayoutsMCPRisk & fraud
Trust center: https://www.aeropay.com/trust-center

Certifications & Compliance

SOC 2Nacha ACH Operating Rules

Source

Trust Center

Raw ↑
generated: '2026-09-10'
method: searched
source: https://www.aeropay.com/trust-center
url: https://www.aeropay.com/trust-center
published: true
certifications:
- name: SOC 2
  status: compliant
  cadence: annual independent audit
  scope: security, availability and confidentiality controls
  report_available: false
  report_type_published: false
  quote: 'Aeropay is SOC 2 compliant, with annual independent audits verifying that our security,
    availability, and confidentiality controls meet enterprise-grade standards.'
- name: Nacha ACH Operating Rules
  status: compliant
  cadence: annual independent audit of ACH processes
  scope: ACH operations
  quote: 'We handle ACH operations in strict compliance with NACHA standards, and undergo annual
    independent audits of our ACH processes.'
practices_claimed:
- OAuth-first bank linking through the Aerosync widget
- FDX-style normalization of bank data
not_claimed:
- PCI DSS
- ISO/IEC 27001
- HIPAA
- FedRAMP
- GDPR certification
third_party_trust_portal:
  present: false
  note: 'No Vanta, Drata, SafeBase or Conveyor trust portal is linked; the trust center is a marketing page
    on the Webflow site, not a document exchange. No SOC 2 report, penetration-test summary, subprocessor
    list or security questionnaire is downloadable, and there is no gated request form for one.'
vulnerability_disclosure:
  present: false
  note: 'The trust center names no vulnerability disclosure policy, responsible disclosure process, bug
    bounty program or security contact address. No /.well-known/security.txt is served on any Aeropay host
    (well-known/aeropay-well-known.yml). probe-security-programs.py returned vdp=none. A researcher who
    finds a flaw in a live payments network has no published channel to report it. NO type: Security
    pointer is emitted in apis.yml because no disclosure program exists to point at.'
jurisdiction:
  countries:
  - US
  note: Aeropay states it currently supports U.S. bank accounts only.
legal:
  privacy_policy: https://www.aeropay.com/legal/privacy-policy
  terms_merchant: https://www.aeropay.com/legal/terms-of-service
  terms_end_user: https://www.aeropay.com/legal/terms-of-service---end-user
evidence:
- url: https://www.aeropay.com/trust-center
  status: 200
- url: https://www.aeropay.com/.well-known/security.txt
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aeropay-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.