Executive Summary
AI-generated analysis for Modern Treasury
Modern Treasury (moderntreasury.com) is a payment operations API platform that has been assessed at Risk Tier 3 (Moderate Risk) with a 90% confidence score, reflecting a vendor with a solid technical security foundation and broad compliance claims that require independent confirmation before approval. The vendor presents several meaningful positive signals:
Key Findings
- Clean threat intelligence posture: zero malicious indicators across Malware detection service, Open Threat Exchange, and website security scanning, with a 0% IP abuse confidence score on a whitelisted CDN address
- Minimal infrastructure exposure with only 2 open ports (80 and 443), representing an exceptionally controlled footprint well below the SaaS industry average of 8–12 open ports, with zero known CVEs
- An established web presence dating to 2018 and no adverse media — either recent or historical — across multiple independent media sources
- A comprehensive trust and security page (https://moderntreasury.com/security) that claims SOC 2 Type II, SOC 1 Type II, PCI DSS 4.0, GDPR/CCPA compliance, and NIST CSF 1.1 alignment
- No sanctions matches, no SEC enforcement filings, and no FDIC regulatory concerns Three areas require attention before this vendor can be moved to approved status. First, all six compliance certifications — including SOC 2 Type II, SOC 1 Type II, and PCI DSS 4.0 — are vendor-attested only; none were independently confirmed through a public registry during this investigation, and the actual audit reports have not been reviewed. Second, Modern Treasury's AI data usage policy, found at https://moderntreasury.com/security, does not clearly state whether customer data is used to train AI models, and the evidence suggests potentially indefinite retention of data processed through AI features — a meaningful gap for a medium data access vendor. Third, the vendor's published subprocessor page (https://trust.moderntreasury.com/subprocessors) was found but could not be parsed, leaving the third-party supply chain unreviewed. Overall, Modern Treasury presents a credible compliance posture and strong technical hygiene for a fintech infrastructure vendor, but the inability to independently verify its certification claims and the ambiguity around AI data practices place it at Tier 3. A conditional approval pathway is available upon receipt of current audit reports and clarification of AI data handling commitments.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation or notification.