PayActiv · Trust Center

Payactiv Trust Center

Trust center

PayActiv maintains a public trust center documenting SOC 2, ISO 27001, PCI DSS, CCPA, Visa Service Provider, and Certified B Corporation compliance.

CompanyFinancial-ServicesEarned Wage AccessPaymentsPayrollHuman ResourcesCardsFinancial WellnessFintech
Trust center: https://payactiv.com/trust-center/

Certifications & Compliance

SOC 2ISO 27001PCI DSSCCPAVisa Service ProviderCertified B Corporation

Source

Trust Center

payactiv-trust-center.yml Raw ↑
generated: '2026-08-04'
method: searched
probe: true
source: https://payactiv.com/trust-center/
url: https://payactiv.com/trust-center/
certifications:
- SOC 2
- ISO 27001
- PCI DSS
- CCPA
- Visa Service Provider
- Certified B Corporation
programs:
- name: Information Security Program
  url: https://payactiv.com/information-security-program/
  summary: >-
    Policies, procedures and standards maintained in accordance with PCI/SOC/ISO controls. Publishes
    encryption at rest and in transit, mandatory multi-factor authentication, annual security training,
    employee background checks, an incident response plan with a reporting mechanism for suspected
    vulnerabilities, and log retention of 180 days minimum (one year for confidential data).
- name: Data Processing Agreement
  url: https://payactiv.com/data-processing-agreement/
  summary: California Consumer Privacy Act compliant data processing terms.
- name: Privacy Policy
  url: https://payactiv.com/privacy-policy/
- name: Compliance Handbook
  url: https://www.payactiv.com/trust-center/compliance-handbook
  summary: EWA program compliance with state and federal wage-and-labor and consumer-protection law.
testing:
  external_penetration_test: at least annually
  internal_penetration_test: twice yearly by an independent third party
  internal_vulnerability_scans: monthly minimum
  external_vulnerability_scans: quarterly minimum, via a PCI Approved Scanning Vendor
  remediation_sla: critical and high severity remediated within 30 days
licensing:
  nmls_id: '2591928'
  ewa_licenses:
  - 'Wisconsin Department of Financial Institutions — EWA license 2591928EWA'
  - 'Connecticut Department of Banking — small loan license SLC-2591928'
  - 'Nevada Financial Institution Division — EWA license EWA00009'
evidence:
- source: https://payactiv.com/trust-center/
  http_status: 200
  keywords: [soc 2, iso 27001, pci dss, ccpa, visa service provider, trust center, b corporation]
- source: https://payactiv.com/information-security-program/
  http_status: 200
  keywords: [pci, soc, iso, encryption, incident response, penetration test]
notes: >-
  No public vulnerability disclosure policy, bug bounty program, or security@ contact was found.
  /.well-known/security.txt returns 404 on payactiv.com; the only published contact is the general
  support address, so no VulnerabilityDisclosure artifact or Security pointer was emitted.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/payactiv-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.