Executive Summary
AI-generated analysis for Razorpay
Razorpay (razorpay.com), a payment solutions provider incorporated as Razorpay Software Limited in India (LEI: 335800MPTXBI8YNP7245), presents a moderate overall risk posture consistent with its Tier 3 designation. The company operates an established platform with a 12-year domain history and clear legal entity registration. Several signals support a positive baseline assessment:
Key Findings
- No sanctions or watchlist matches were identified across OFAC, EU, and UN screening databases.
- No adverse media was detected in either the 12-month primary scan or the historical archive search.
- Infrastructure exposure is minimal, with only 2 open ports (80 and 443) and zero known CVEs — well below the SaaS industry average of 8–12 open ports, reflecting a tightly controlled and CDN-protected attack surface.
- Malware detection service and IP reputation checks returned clean results with no malware, phishing, or abuse signals.
- Razorpay claims SOC 2 compliance on its trust page, and a possible HITRUST directory match was identified, though both require independent verification. Three areas warrant attention before or during onboarding. First, Razorpay's subprocessor page at trust.razorpay.com/subprocessors exists but currently contains placeholder content, preventing automated supply chain analysis — a meaningful gap for GDPR Article 28 and SOC 2 CC9.2 compliance documentation. Second, the vendor's AI data usage policy does not clearly state whether customer data is used for model training or specify data retention periods for AI processing, which creates ambiguity for data-sensitive workloads. Third, the marketing site scored C+ on HTTP security headers (60/100), though the application endpoint (dashboard.razorpay.com) should be assessed separately before drawing conclusions about the production environment. Overall, Razorpay demonstrates a credible compliance posture for a major payment infrastructure provider, but several documentation gaps — particularly around subprocessors and AI data handling — should be resolved before the vendor is considered fully cleared for data-sensitive or audit-scope use cases. A conditional approval is warranted pending satisfaction of the requirements outlined in this report.
Independence Statement
All evidence in this report was sourced independently from public registries, open-source intelligence databases, and external scanning infrastructure without vendor participation or notification.