Executive Summary
AI-generated analysis for Currencycloud
Currencycloud is a cross-border payments infrastructure provider (a Visa subsidiary) assessed at Tier 3 (Moderate Risk) with a 92% confidence score, reflecting a generally stable operational profile tempered by several compliance transparency gaps that warrant attention before onboarding. The vendor presents a number of meaningful positive signals:
Key Findings
- The domain is 18+ years established, registered via enterprise registrar MarkMonitor, and protected through Cloudflare's CDN infrastructure, which also provides DDoS mitigation and clean IP reputation (0% abuse score).
- No adverse media, sanctions matches, enforcement actions, or malware/phishing indicators were found across any source queried during this investigation.
- Email routing is handled through Visa's portal infrastructure (portal1i–4i.visa.com), consistent with Currencycloud's status as a Visa-owned entity and providing an additional layer of corporate infrastructure credibility.
- Legal entity registrations for CURRENCYCLOUD PTY LTD and CURRENCYCLOUD B.V. are confirmed active, with BIC codes present in the ISO 9362 registry — consistent with a regulated payments business.
- A possible match was identified in the HITRUST directory, though match confidence does not meet the threshold for confirmed certification; manual verification is recommended. Several concerns merit follow-up before finalising vendor onboarding:
- No SOC 2 claim was detected on the vendor's website or trust pages, and no Type II report was independently located. For a payments infrastructure provider with medium data access, the absence of a publicly surfaced SOC 2 claim is a notable gap in the compliance audit chain and creates a documentation risk for your own SOC 2 CC9.2 obligations.
- ISO 27001 certification was not found via the IAF CertSearch public registry, and no claim appeared on the vendor's trust pages.
- Eleven open ports are exposed on the vendor's external infrastructure — above the typical SaaS baseline — though all are consistent with Cloudflare-proxied web services and no CVEs were identified.
- The vendor's AI data usage policy does not clearly state whether customer data is used for model training, leaving an important privacy and compliance question unresolved.
- HTTP security headers are incomplete (missing Content-Security-Policy and X-Frame-Options), and the site received a C+ grade on security header testing. Overall, Currencycloud is a well-established, Visa-backed payments infrastructure provider with a clean threat intelligence profile. The Tier 3 rating reflects the combination of compliance documentation gaps — particularly the absence of a surfaced SOC 2 report and unclear AI training practices — rather than any active threat indicators. A conditional approval is appropriate pending resolution of the documented requirements below.
Independence Statement
All evidence in this report was independently sourced from external data providers without vendor participation, notification, or input.