Square · Trust Center

Square Trust Center

Trust center

Square's payments security & compliance posture, captured from Square's public secure-payments and PCI compliance pages. Square is the merchant of record and maintains its own PCI certification so sellers do not individually validate compliance; card processing systems meet PCI Data Security Standard Level 1 (the most stringent level, for processors handling 6M+ transactions/year). Sellers who use the Web Payments SDK / hosted surfaces keep card data off their own servers, qualifying for the lightest PCI SAQ A scope. This is the searched, human-verified fill (the automated trust-center probe requires a trust./keyword-threshold page Square does not expose).

Square maintains a public trust center documenting PCI DSS, PCI SAQ A, ISO 27001, and EMVCo compliance.

RestaurantBookingsCatalogCheckoutCustomersDisputesE-CommerceFinancial TechnologyGift CardsInventoryInvoicingLaborLocationsLoyaltyMerchantsOrderPaymentsPoint-of-SaleRefundsRetailSubscriptionTeamTerminalWebhook
Trust center: https://squareup.com/us/en/payments/secure

Certifications & Compliance

PCI DSSPCI SAQ AISO 27001EMVCo

Source

Trust Center

Raw ↑
generated: '2026-07-14'
method: searched
probe: false
source: https://squareup.com/us/en/payments/secure
url: https://squareup.com/us/en/payments/secure
description: >-
  Square's payments security & compliance posture, captured from Square's public
  secure-payments and PCI compliance pages. Square is the merchant of record and
  maintains its own PCI certification so sellers do not individually validate
  compliance; card processing systems meet PCI Data Security Standard Level 1 (the
  most stringent level, for processors handling 6M+ transactions/year). Sellers
  who use the Web Payments SDK / hosted surfaces keep card data off their own
  servers, qualifying for the lightest PCI SAQ A scope. This is the searched,
  human-verified fill (the automated trust-center probe requires a
  trust.<domain>/keyword-threshold page Square does not expose).
certifications:
  - {name: PCI DSS, level: Level 1 (Service Provider), note: Square's card processing systems meet the most stringent PCI Data Security Standard level; Square maintains certification as merchant of record.}
  - {name: PCI SAQ A, scope: sellers, note: Sellers using the Web Payments SDK / hosted checkout keep card data off their servers and qualify for SAQ A (the lightest self-assessment).}
  - {name: ISO 27001, note: Square states its systems are ISO 27001 aligned/certified for information security management.}
  - {name: EMVCo, scope: Square card readers and Terminal, note: EMV chip and contactless acceptance; contactless symbol used under license from EMVCo.}
security_features:
  - End-to-end encryption of card data from capture through processing.
  - Tokenization — card details are replaced with single-use / stored tokens; raw PANs never touch the seller server when using Square SDKs.
  - Built-in fraud detection and risk evaluation on payments (see risk_evaluation in sandbox).
  - Dispute / chargeback handling via the Disputes API.
compliance_model: >-
  Square operates as the merchant of record and handles PCI audits, SAQs,
  vulnerability scanning, and remediation on the seller's behalf; compliance is
  included in the processing fee.
docs:
  - https://squareup.com/us/en/payments/secure
  - https://squareup.com/us/en/the-bottom-line/operating-your-business/pci-compliance
  - https://developer.squareup.com/docs/build-basics/general-requirements
evidence:
  - {source: https://squareup.com/us/en/payments/secure, keywords: [pci certification, merchant of record, end to end, encryption]}
  - {source: https://squareup.com/us/en/the-bottom-line/operating-your-business/pci-compliance, keywords: [pci dss level 1, saq, iso 27001]}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/square-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.