GoFundMe · Trust Center

Gofundme Trust Center

Trust center

GoFundMe maintains a public trust center documenting PCI DSS, NIST Cybersecurity Framework, and ISO 27001 compliance.

FundraisingNonprofitCrowdfundingDonationsPaymentsPeer-to-Peer FundraisingRecurring GivingEventsPhilanthropySocial ImpactCRMWebhooks
Trust center: https://www.gofundme.com/c/security

Certifications & Compliance

PCI DSSNIST Cybersecurity FrameworkISO 27001

Source

Trust Center

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
url: https://www.gofundme.com/c/security
name: GoFundMe Security
note: >-
  There is no dedicated trust-center subdomain (trust.gofundme.com and security.gofundme.com do not
  resolve; a trust-portal probe returned nothing). GoFundMe publishes its security and compliance
  posture as a single page on the main site, which is where the certifications below are named.
certifications:
- name: PCI DSS
  level: Level 1 Service Provider
  status: certified
  detail: >-
    Audited annually by an independent PCI Qualified Security Assessor; listed on the Visa Global
    Registry of Service Providers. Attestation of Compliance available on request.
- name: NIST Cybersecurity Framework
  status: aligned
  detail: Program aligned to NIST CSF with controls drawn from NIST 800-53 and CIS CSC Top 20.
- name: ISO 27001
  status: inherited
  detail: Cited for the AWS hosting infrastructure, not held by GoFundMe itself.
practices:
  encryption_in_transit: TLS 1.2+ with AES-256
  encryption_at_rest: FIPS-approved AES-256
  hosting: AWS
  sdlc:
  - Risk assessments based on the OWASP Top 10
  - Static, dynamic and software composition analysis
  - Mandatory secure-coding training for developers
bug_bounty:
  program: private
  platform: Bugcrowd
  paid: true
  detail: >-
    GoFundMe runs a private bug bounty with Bugcrowd. Researchers outside the program may still
    submit via the form on the security page. Accepted unknown findings are eligible for payment.
    Public disclosure of findings requires prior written approval.
  in_scope_domains:
  - gofundme.com
  - api.gofundme.com
  - funds.gofundme.com
  - gateway.gofundme.com
external_references:
- https://usa.visa.com/splisting/splistingindex.html
- https://aws.amazon.com/security/
evidence:
- source: https://www.gofundme.com/c/security
  keywords: [pci dss, level 1 service provider, nist cybersecurity framework, owasp top 10, bugcrowd, aws, iso 27001]
  fetched: '2026-08-04'
  http_status: 200
gaps:
- No SOC 2 Type II report or attestation is named publicly.
- No trust portal / compliance document request flow beyond "available upon request".
- >-
  The compliance posture covers the consumer GoFundMe platform; nothing equivalent is published on
  the GoFundMe Pro developer surface for the API itself.