Executive Summary
AI-generated analysis for Remitly
Remitly (remitly.com) is an established international money transfer platform that has been assigned a Tier 3 (Moderate Risk) rating by ThirdProof's rule engine, reflecting a generally strong security posture alongside several compliance documentation gaps that warrant attention before or during vendor onboarding. Remitly demonstrates meaningful positive signals across multiple risk domains:
Key Findings
- The domain has been registered since 2012 and archived since 2013, establishing over 14 years of continuous online presence.
- HTTP security scanner awarded remitly.com an A+ grade (110/100), indicating excellent HTTP security header configuration — a benchmark few SaaS vendors achieve.
- Infrastructure exposure is minimal, with only 2 open ports (80 and 443) detected and zero known CVEs — well below the SaaS industry average of 8–12 open ports, representing a tightly controlled external attack surface.
- TLS configuration uses TLSv1.3 with a modern cipher suite (TLS_AES_128_GCM_SHA256), and the certificate is issued by Amazon with no weak protocols detected.
- The domain resolves through Cloudflare CDN infrastructure, adding a layer of DDoS and network-edge protection.
- No adverse media was identified in either the 12-month scan or historical archive search. No sanctions, watchlist, or OFAC matches were found. Malware detection service and IP abuse checks returned clean results.
- Remitly Global is a publicly traded company (NASDAQ: RELY), and no SEC enforcement filings were identified in EDGAR searches.
- A legal entity registration (LEI: 549300ZFMWSXLGV3QC86) is active for Remitly U.K., Ltd in Great Britain, confirming formal regulatory standing in at least one jurisdiction. Two areas require active follow-up. First, no SOC 2 claim was detected on Remitly's trust pages (remitly.com/security, remitly.com/security/compliance, remitly.com/legal/compliance), and no ISO 27001 certification was found via independent registry search. For a company handling financial transfers, this is a notable compliance documentation gap — the absence of a published SOC 2 claim does not mean no audit exists, but it creates an unresolved evidence gap for buyers seeking audit chain continuity. Second, Remitly's AI data usage policy does not clearly disclose whether customer data may be used for model training, and no third-party AI providers or retention commitments are named. With Remitly publicly promoting AI-powered support features, this ambiguity warrants direct clarification. Overall, Remitly presents as a well-established, technically sound vendor with strong infrastructure hygiene and a clean adverse media and sanctions profile. The Tier 3 rating reflects the unresolved compliance documentation gaps — particularly the absent SOC 2 evidence and unclear AI data practices — rather than any affirmative security concern. Conditional approval is appropriate, subject to receipt of current compliance documentation and clarification of AI data handling commitments.
Independence Statement
All evidence in this report was independently sourced from external registries, public threat intelligence feeds, and open-source data — Remitly did not participate in or contribute to this investigation.