Executive Summary
AI-generated analysis for Plaid
Plaid (plaid.com) is a well-established financial technology infrastructure provider rated Tier 3 (Moderate Risk) by ThirdProof's rule engine, reflecting a vendor with strong foundational security signals offset by several areas requiring closer scrutiny from procurement and compliance teams. Plaid demonstrates meaningful security maturity across several dimensions:
Key Findings
- The domain has been registered and continuously archived since the mid-1990s, reflecting a long-established and stable entity.
- Infrastructure exposure is minimal: only 2 open ports (80 and 443) with zero known CVEs detected — well below the SaaS industry average of 8–12 open ports, representing a tightly controlled footprint.
- Malware detection service, IP reputation checks, and website security scans all return clean results with a threat score of 0.
- Plaid claims SOC 2 (SSAE18) compliance and ISO 27001 and ISO 27701 certifications on its public security page (https://plaid.com/security), and a possible HITRUST directory match was detected pending manual verification.
- No sanctions matches, adverse media, SEC enforcement actions, or FDIC regulatory concerns were identified.
- Plaid maintains a legal entity registration active in the Netherlands (LEI: 7245006VF0O83RBSW372), providing corporate traceability. Several findings warrant attention before or during onboarding:
- Plaid's two key certifications (SOC 2 and ISO 27001) are vendor-attested only — independent registry confirmation was not available at the time of this assessment. The actual Type II report and ISO certificate should be requested directly.
- The marketing site (plaid.com) received a D+ grade (40/100) from Mozilla HTTP Observatory, with missing Content-Security-Policy and X-Frame-Options headers. Plaid operates a separate application domain (secure.plaid.com) which was not evaluated in this scan and may have stronger controls.
- Fifty community threat intelligence pulses reference plaid.com, primarily associated with "Operation Endgame" clone entries. This pattern is consistent with a high-profile financial infrastructure domain being referenced in threat research campaigns rather than indicating compromise of Plaid itself — however, it warrants documentation.
- No subprocessor list was publicly discoverable, limiting supply chain visibility for GDPR and SOC 2 audit purposes.
- Plaid discloses use of third-party AI providers (OpenAI and Anthropic) but does not clearly articulate whether customer data is used to train AI models, and no AI-specific data retention period was specified. Overall, Plaid presents as a credible, mature vendor with no critical risk indicators. A conditional engagement posture is appropriate, requiring certification verification, subprocessor disclosure, and AI data handling clarification before full onboarding.
Independence Statement
All evidence in this report was independently sourced by ThirdProof from external data providers and public registries without vendor participation or notification.