Braintree Trust Center
Braintree's security & compliance posture, captured from the Braintree PCI compliance documentation and the PayPal Trust Center. Braintree (a PayPal service) is validated as a PCI DSS Level 1 Service Provider — the most stringent level in the payments industry — and appears on Visa's Global Registry of Service Providers and Mastercard's SDP list. Braintree never stores raw magnetic-stripe, CVV, or PIN-block data; cardholder data in the Vault is encrypted with multiple keys under split-knowledge / dual-control. Merchants still complete an annual SAQ (typically SAQ A when using Hosted Fields, Drop-in, mobile SDKs, or GraphQL).
Braintree maintains a public trust center documenting PCI DSS, Visa Global Registry of Service Providers, Mastercard SDP, and SOC 2 Type 2 compliance.
Certifications & Compliance
Source
Trust Center
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.