SaaSDossier

No. 001 · Licensed Edition

Stripe — Security Evidence Dossier

Question
What security evidence does Stripe publish?
Answer
Stripe publishes broad public security documentation — SOC 2 Type II and PCI DSS Level 1, a GDPR-aligned data-processing agreement, AES-256 at rest with TLS in transit, single sign-on and multi-factor access, a public subprocessor list, and 48-hour incident notification. Of 55 fields, 46 are Documented and 9 are Questions surfaced for buyer follow-up.
46 Documented9 Questions surfacedof 55
Cover of the Stripe Security Evidence Dossier — Licensed Edition, Dossier No. 001
Edition
Licensed Edition
Reference
Dossier No. 001
Framework
55 fields · 10 domains
Documented
46 of 55
Questions surfaced
9
Evidence date
22 June 2026
Release date
2026-07-02
Vendor pages reviewed
14
Price
US$1,500 — Licensed Edition

10 domains reviewed

  • Identity & legal entity
  • Standards & attestations
  • Privacy & compliance
  • Encryption & key management
  • Infrastructure & hosting
  • Access control
  • Vulnerability & incident response
  • Subprocessors & supply chain
  • AI governance
  • Secure development & organization

A sample of the evidence ledger

A preview of the discipline — one Documented, one Question surfaced. The full 55-field ledger is in the dossier.

Documented
PCI DSS Level 1
Question surfaced
ISO/IEC 27001

What's inside

Evidence ledger

All 55 fields across 10 domains, each recorded in one of two states, with the vendor's own words quoted and cited where Documented.

Source register

Every vendor-published page reviewed, listed with its URL, so each line traces back to where it was found.

Integrity record

Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release.

Buyer-ready vendor follow-up questions

Field-level follow-ups generated from Question surfaced entries, used to help buyers decide what to confirm with the vendor in writing.

Question surfaced means: Reviewed vendor-published sources did not establish the field for the evidence date. This does not establish absence of the control.

What this adds beyond a trust center

A vendor trust center can show what the vendor chooses to publish. SaaSDossier reads vendor-published sources against the same 55-field framework and separates fields marked Documented from fields marked Question surfaced. The value is not replacing the vendor's SOC 2, DPA, or trust portal. The value is a dated, source-linked review record your team can use before the vendor call.

Licensed Edition use

  • For use within one purchasing organization.
  • Unlimited internal users inside that organization.
  • Excerpts may be shared with external auditors, vCISOs, counsel, procurement reviewers, or GRC advisors under confidentiality.
  • Redistribution, resale, public posting, or use as a competing dataset is not permitted.

Using this record for a vendor security questionnaire or DDQ? See how SaaSDossier supports the review without completing or deciding it for you.