Affirm

Affirm publicly advertises 4 compliance frameworks through a trust center hosted by SafeBase.

Fintech & Financial Services

4

Advertised frameworks

SafeBase

Trust center platform

First observed

Founding to trust center

Affirm Holdings, Inc. is an American financial technology company and a point-of-sale lender.

Summary from Wikipedia.

Publicly advertised compliance posture

As observed on September 8, 2026 on the organization’s public trust center.

  • CCPA

    Publicly advertised on the organization’s trust center.

  • PCI DSS

    Payment card industry standard for handling cardholder data securely.

  • SOC 1

    Publicly advertised on the organization’s trust center.

  • SOC 2

    Independent CPA audit of controls for security, availability, and confidentiality.

Compliance timeline

  1. 2012

    Company founded

  2. September 8, 2026

    Posture last observed by Trust Index

Security & compliance hiring

Open roles on the organization’s public job board, a signal of active investment in security and compliance.

  • Analytics Lead, Strategic Insights (Compliance)
  • Bank Compliance Technology Analyst
  • Compliance Manager
  • Compliance Manager (Australia)
  • Director, Information Technology & Security
  • Financial Model Risk Management Lead
  • Financial Model Risk Management Lead
  • Model Risk Management Lead, Machine Learning
  • Model Risk Management Lead, Machine Learning
  • Product Security Engineer II
  • Quantitative Analytics Manager, Affirm Bank Model Governance
  • Security Risk Management Lead
  • Security Risk Management Specialist II
  • Security Risk Management Specialist II
  • Senior Director, Enterprise Risk Strategy
  • Senior Software Engineer , Frontend (Trust & Safety)
  • Underwriting/Credit Model Risk Senior Manager - Machine Learning
  • Underwriting/Credit Model Risk Senior Manager - Machine Learning

About this data

The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.

More in Fintech & Financial Services

How can we work together

Schedule a discovery session

A complimentary, exploratory meeting to discuss your business goals and challenges, identify potential solutions, and determine if our services align with your needs.

Hire us for a project

Augmenting a specific initiative or project, leveraging our expertise and resources to deliver a defined outcome.

Retain us long term

Ongoing collaboration and support through regular meetings, check-ins, and access to our team's collective knowledge and experience, empowering you to make informed decisions and drive sustained growth.