Tech-driven payments solutions for your business
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Coinflow discloses on its trust center. Linked entries have their own profile in the Trust Index.
58% chain trust: 15 of 26 disclosed subprocessors are themselves in the Trust Index.
- Attio CRM
- Basis Theory Card Tokenisation
- Render Cloud provider
- MongoDB Data storage and processing
- Intuit Finance and payments
- Ixopay Card Tokenisation
- Dialpad Customer support
- LexisNexis Risk Management
- Metakeep Security
- Nsure.ai Transaction data analytics
- Nuvei Finance and payments
- Oscilar Risk and AML
- Persona IDVA
- Plaid Finance and payments
- Shift4 Finance and payments
- SumSub KYC KYC
- Worldpay Finance and payments
- Elastic Security
- evervault Security
- Google Document management
- Rain Finance and payments
- SigNoz Cloud monitoring
- Supabase Engineering
- TRM Labs, Inc. Security
- Vanta Security
- Verisoul Finance and payments
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.