Airalo is a telecommunications company founded in 2019 by Ahmet Bahadir Özdemir and Abraham Burak, and sells eSIMs. It's headquartered in Delaware, with its operational base in Singapore.
Summary from Wikipedia.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
Compliance timeline
-
2019
Company founded
-
July 2024
Trust center first observed in public web archives
-
September 8, 2026
Posture last observed by Trust Index
Roughly 5 years elapsed between founding and the earliest archived capture of a public trust center. Archive coverage is incomplete, so the page may have existed earlier.
Subprocessors
Third parties Airalo discloses on its trust center. Linked entries have their own profile in the Trust Index.
64% chain trust: 14 of 22 disclosed subprocessors are themselves in the Trust Index.
- Amazon Web Services Infrastructure Hosting
- Google Workspace Email and Workspace
- Cloudflare Cloud monitoring and Content distribution
- Datadog Cloud monitoring
- Zendesk Support Ticket Tool, In-Application Support Chat
- Atlassian, Inc. Ticketing and project management
- Slack Internal Communications
- Notion Knowledge base and Collaboration
- DocuSign Document management
- Clevertap Marketing
- Ably Real-time notifications
- Stripe Finance and payments
- PayPal Finance and payments
- ddroidd Professional services
- Transcom Customer support
- Affluent, Inc. Affiliate and marketing management
- Adjust Inc. Targeted marketing
- HubSpot, Inc. Marketing platform and lead management
- Impact Tech, Inc. Affiliate and marketing management
- Postmark Transactional and marketing emails
- Typeform Survey Platform and feedback
- Hotjar Data analytics
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.