Onbe | Trust Center
A world of payout choice. One standard of trust.
Onbe stands for "on behalf." Clients trust us with their payouts precisely so they don't have to carry the cost, risk, and complexity in-house, with over $100B moved to date, across 170+ countries. That trust is earned in the controls behind every payment. Verify them here.
See Compliance Frameworks

Resources

Documents and Reports

Onbe Security Whitepaper

PCI DSS v4.0.1 Attestation of Compliance

SOC 1 Type II Report

SOC 1 Type II Bridge Letter

SOC 2 Type II Audit Report

SOC 2 Type II Bridge Letter

Information Security Policy

User Access & Control Policy

Network Security Policy

Data Retention Policy

View all

Subprocessors

Third Party Associates Sub processor usage is program specific, and not all sub processors are engaged for every client or product. Each sub processor is subject to contractual data protection requirements and ongoing third-party risk and compliance oversight. Onbe is committed to protecting the confidentiality, integrity, and availability of customer and partner data.

FISERV

Onbe uses Fiserv, Inc. as a transaction processor and physical card fulfillment partner for applicable programs. In this capacity, Fiserv functions as a data sub‑processor and may process customer or end‑user data as necessary to perform contracted processing and fulfillment services on Onbe’s behalf.

FIS

Onbe engages Fidelity Information Systems, LLC (FIS) as a transaction processing service provider for certain payment and card‑related program functions. FIS acts as a data sub‑processor and processes data only as required to support authorized transaction processing activities on behalf of Onbe.

Arroweye

Onbe uses Arroweye Solutions, Inc. as a physical card fulfillment provider for applicable programs. In this role, Arroweye acts as a data sub‑processor and may process limited personal data strictly as necessary to support card production and fulfillment services on behalf of Onbe.

Microsoft

Onbe uses Microsoft Azure as a cloud infrastructure provider to host components of the Onbe platform. In this capacity, Microsoft acts as a data sub‑processor, providing secure computing, storage, and availability services that may involve the processing of customer or end‑user data on behalf of Onbe.

Compliance

Information Security Frameworks Onbe aligns its security, privacy, and compliance program with recognized industry standards and regulatory frameworks to support customer, partner, and regulatory expectations. Key frameworks include SOC 2 Type II for security, availability, and confidentiality controls; PCI DSS v4 for the protection of cardholder data; and global and U.S. privacy frameworks such as GDPR and CPRA/CCPA. Our product security program is designed to reduce risk, support regulatory and customer expectations, and transparently communicate how security is embedded across our technology, people, and processes. This Trust Center summarizes our security posture and provides a structured view of the controls, measures and frameworks supporting our platforms.

PCI

PCI DSS (Payment Card Industry)

SOC 1

System and Organization Controls 1

SOC 2

System and Organization Controls 2

CCPA

California Consumer Privacy Act

GDPR

The General Data Protection Regulation

FAQs

Onbe maintains compliance across payments, privacy, and industry-specific regulation. We are assessed annually against PCI DSS v4.0.1 as a Level 1 Service Provider, and we maintain SOC 1 Type II and SOC 2 Type II audit reports. Our solutions comply with Regulation E, the NACHA Operating Rules, GLBA, and OFAC sanctions requirements. On privacy, Onbe follows GDPR and UK GDPR, CCPA/CPRA and other U.S. state privacy laws, and in Canada, PIPEDA, Quebec Law 25, and the Code of Conduct for the Credit and Debit Card Industry. Where we act as a Business Associate, we also maintain HIPAA Security Rule safeguards.
Yes. Our Security Whitepaper, PCI DSS Attestation of Compliance, and SOC reports together answer the majority of standard questionnaire items; request them above. If you have additional questions, please reach out to your Onbe account executive or sales contact.
Please see the Resources section above to view or request these documents.
Onbe stores, processes, and transmits cardholder data in the course of delivering prepaid card and payout programs, and is assessed annually against PCI DSS as a service provider. Primary Account Numbers are rendered unreadable wherever they are stored and are masked in our applications and reporting. Card issuing, transaction processing, and physical card fulfillment are performed by PCI DSS-validated partners. The precise boundary of Onbe's assessed environment is described in our Attestation of Compliance.
Internal access is granted on a least-privilege, need-to-know basis, tied to job role, and approved before provisioning. Multi-factor authentication is required for access to all sensitive systems. Entitlements are reviewed on a recurring schedule and revoked on role change or termination, and privileged access is restricted to a limited set of named administrators subject to additional approval.
Data is encrypted in transit over public networks using TLS 1.2+, and encrypted at rest using AES-256. Encryption keys are managed in a dedicated key management service with access restricted to authorized personnel.
Onbe operates centralized logging and security monitoring across its Azure environment, corporate endpoints, and identity systems. Security-relevant events, endpoint, and identity telemetry are monitored for malicious activity, and alerts are triaged by the security team. Network traffic is filtered by next-generation firewalls, internet-facing applications sit behind a web application firewall, and access to production systems is audited on a recurring basis.
Yes. Independent third-party penetration tests are performed at least annually against in-scope environments. Vulnerability scanning runs on a recurring schedule across internal and external assets, and findings are tracked to remediation on timelines set by severity.
Onbe maintains a documented incident response plan covering detection, triage, containment, eradication, recovery, and post-incident review, with defined severity levels, escalation paths, and named responsibilities. The plan is exercised and reviewed at least annually, and lessons learned feed back into our controls. Where Onbe confirms a security incident affecting a client's data, we notify that client without undue delay and in accordance with the notification requirements of their agreement and applicable law. Specific notification timeframes are defined contractually.
Yes. Onbe maintains business continuity and disaster recovery plans for its platform and operations, and plans are tested on a recurring basis. Availability controls are independently tested in our SOC 2 Type II examination.
View all

Monitoring