Square · Trust Center

Square Trust Center

Trust center

Square's payments security & compliance posture, captured from Square's public secure-payments and PCI compliance pages. Square is the merchant of record and maintains its own PCI certification so sellers do not individually validate compliance; card processing systems meet PCI Data Security Standard Level 1 (the most stringent level, for processors handling 6M+ transactions/year). Sellers who use the Web Payments SDK / hosted surfaces keep card data off their own servers, qualifying for the lightest PCI SAQ A scope. This is the searched, human-verified fill (the automated trust-center probe requires a trust./keyword-threshold page Square does not expose).

Square maintains a public trust center documenting PCI DSS, PCI SAQ A, ISO 27001, and EMVCo compliance.

RestaurantBookingsCatalogCheckoutCustomersDisputesEcommerceFinancial TechnologyGift CardsInventoryInvoicingLaborLocationsLoyaltyMerchantsOrdersPaymentsPoint of SaleRefundsRetailSubscriptionsTeamTerminalWebhooks
Trust center: https://squareup.com/us/en/payments/secure

Certifications & Compliance

PCI DSSPCI SAQ AISO 27001EMVCo

Source

Trust Center

Raw ↑
generated: '2026-07-14'
method: searched
probe: false
source: https://squareup.com/us/en/payments/secure
url: https://squareup.com/us/en/payments/secure
description: >-
  Square's payments security & compliance posture, captured from Square's public
  secure-payments and PCI compliance pages. Square is the merchant of record and
  maintains its own PCI certification so sellers do not individually validate
  compliance; card processing systems meet PCI Data Security Standard Level 1 (the
  most stringent level, for processors handling 6M+ transactions/year). Sellers
  who use the Web Payments SDK / hosted surfaces keep card data off their own
  servers, qualifying for the lightest PCI SAQ A scope. This is the searched,
  human-verified fill (the automated trust-center probe requires a
  trust.<domain>/keyword-threshold page Square does not expose).
certifications:
  - {name: PCI DSS, level: Level 1 (Service Provider), note: Square's card processing systems meet the most stringent PCI Data Security Standard level; Square maintains certification as merchant of record.}
  - {name: PCI SAQ A, scope: sellers, note: Sellers using the Web Payments SDK / hosted checkout keep card data off their servers and qualify for SAQ A (the lightest self-assessment).}
  - {name: ISO 27001, note: Square states its systems are ISO 27001 aligned/certified for information security management.}
  - {name: EMVCo, scope: Square card readers and Terminal, note: EMV chip and contactless acceptance; contactless symbol used under license from EMVCo.}
security_features:
  - End-to-end encryption of card data from capture through processing.
  - Tokenization — card details are replaced with single-use / stored tokens; raw PANs never touch the seller server when using Square SDKs.
  - Built-in fraud detection and risk evaluation on payments (see risk_evaluation in sandbox).
  - Dispute / chargeback handling via the Disputes API.
compliance_model: >-
  Square operates as the merchant of record and handles PCI audits, SAQs,
  vulnerability scanning, and remediation on the seller's behalf; compliance is
  included in the processing fee.
docs:
  - https://squareup.com/us/en/payments/secure
  - https://squareup.com/us/en/the-bottom-line/operating-your-business/pci-compliance
  - https://developer.squareup.com/docs/build-basics/general-requirements
evidence:
  - {source: https://squareup.com/us/en/payments/secure, keywords: [pci certification, merchant of record, end to end, encryption]}
  - {source: https://squareup.com/us/en/the-bottom-line/operating-your-business/pci-compliance, keywords: [pci dss level 1, saq, iso 27001]}