Razorpay · Trust Center

Razorpay Trust Center

Trust center

Razorpay's security & compliance posture, captured from razorpay.com/docs/security and the published PCI DSS certificate. Razorpay is a PCI-DSS certified payment service provider handling cardholder data, with its cardholder data environment assessed by an external QSA (Ampcus Cyber). Compliance program covers PCI-DSS, ISO 27001, and SOC 2. Certificate copies are provided on request via a Key Account Manager, so the automated trust-center probe (which requires a trust. subdomain and keyword threshold) does not record it — this is the searched, human-verified fill.

Razorpay maintains a public trust center documenting PCI DSS, ISO 27001, and SOC 2 compliance.

PaymentsPayment GatewayFintechIndiaUPISubscriptionPayoutsCheckout
Trust center: https://razorpay.com/docs/security/

Certifications & Compliance

PCI DSSISO 27001SOC 2

Source

Trust Center

Raw ↑
generated: '2026-07-14'
method: searched
probe: false
source: https://razorpay.com/docs/security/
url: https://razorpay.com/docs/security/
description: >-
  Razorpay's security & compliance posture, captured from razorpay.com/docs/security
  and the published PCI DSS certificate. Razorpay is a PCI-DSS certified payment
  service provider handling cardholder data, with its cardholder data environment
  assessed by an external QSA (Ampcus Cyber). Compliance program covers PCI-DSS,
  ISO 27001, and SOC 2. Certificate copies are provided on request via a Key
  Account Manager, so the automated trust-center probe (which requires a
  trust.<domain> subdomain and keyword threshold) does not record it — this is
  the searched, human-verified fill.
certifications:
  - {name: PCI DSS, scope: Payment service provider — cardholder data environment, assessor: Ampcus Cyber Inc. (QSA), note: Certificate published; copies available on request.}
  - {name: ISO 27001, note: Information security management system compliance.}
  - {name: SOC 2, note: Part of Razorpay's stated global compliance program.}
data_protection:
  transport: HTTPS/TLS with industry-standard ciphers; EV SSL certificate.
  encryption_at_rest: AES-128-bit encryption for user data.
  pii: Field-level encryption for personally identifiable information.
report_access:
  method: Certification copies provided on request via a Key Account Manager.
docs:
  - https://razorpay.com/docs/security/
  - https://razorpay.com/docs/security/shared-responsibility-model/
  - https://razorpay.com/docs/build/browser/assets/images/pci-dss-us.pdf
evidence:
  - {source: https://razorpay.com/docs/security/, keywords: [pci-dss, tls, aes-128, ev ssl, field-level encryption]}
  - {source: https://www.ampcuscyber.com/certificate/razorpay-pci-dss-coc.pdf, kind: pci-dss-certificate}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/razorpay-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.