Expensify, Inc. is an American software company that develops an expense management system for personal and business use.
Summary from Wikipedia.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 1
Publicly advertised on the organization’s trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
CCPA
Publicly advertised on the organization’s trust center.
Compliance timeline
-
2008
Company founded
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Expensify discloses on its trust center. Linked entries have their own profile in the Trust Index.
63% chain trust: 20 of 32 disclosed subprocessors are themselves in the Trust Index.
- Amazon Web Services Cloud Infrastructure Provider
- Cloudflare Cloud Security and Infrastructure
- DocuSign Document Management
- GitHub Version Control
- Google Drive Document management
- Evocative Data Center Provider
- Switch Data Center Provider
- Airship Customer Notification Delivery
- The Bancorp Bank, N.A. Payment Processor
- Calendly Meeting Scheduling
- Checkbook Payment Processor
- Clearbit Account Configuration
- CloudFactory Receipt Scanning
- Cloudtask Sales and Support
- Collective Solutions Receipt Scanning
- Ashby Recruiting
- FullStory Product and design
- Gong Sales
- Google Workspace Identity provider
- HubSpot CRM
- Ketch Privacy Orchestrator Privacy rights management
- OpenAI LLM model provider
- Plaid Transaction import
- Mailgun Email sending
- Sentry Application monitoring
- Slack Internal chat system
- Stripe Credit card billing
- Twilio Text message provider
- Vanta Security
- Typeform Customer questionnaires
- Zapier Internal automation system
- Zoom Video conferencing
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.