Security and privacy you can rely on
Independently certified and audited




Explore the SurePay Trust Center

DORA Addendum
EU’s Digital Operational Resilience Act (DORA), supplements the provisions for ICT risk management, incident reporting, and audit rights to safeguard critical financial services.
DOWNLOAD PDF →
Data Processing Agreement
This DPA supplements the provisions for managing personal data in compliance with applicable privacy laws.

Non-disclosure Agreements
Download the NDA for your region below.

Ecovadis Scorecard
SurePay’s latest sustainability and corporate social responsibility assessment, as rated by EcoVadis. Customers can request access to our EcoVadis Scorecard directly via the EcoVadis platform.
Go to ecovadis →
Yearly Financial Audit
Independently audited by EY to ensure full financial transparency and compliance. Results are available for review upon discussion.

Statement on Modern Slavery and Human Trafficking
This statement applies to SurePay B.V. and SurePay Ltd (collectively “SurePay”).
DOWNLOAD PDF →
SurePay: Code of Conduct
This Code of Conduct applies to everyone who works at and with SurePay
DOWNLOAD PDF →Key information on security, compliance and privacy
Security Standard:
At SurePay, the security of personal data and the integrity of our services are our highest priorities. We employ a comprehensive, multi-faceted security strategy, protecting all personal data with strong encryption both at rest and in transit. Our security model is centered on the principle of least privilege, enforced through formal user management processes, mandatory multi-factor authentication (MFA). Our network utilizes a defense-in-depth approach with strict segmentation between production and non-production environments and other best practices. We proactively manage threats using 24/7 monitoring, frequent vulnerability scanning, and proactive threat modeling, while also integrating security directly into our development lifecycle. This entire framework is supported by our people, who complete background checks and mandatory annual security and privacy training. We also have resiliency in form of auto scaling, multi AZ and multi region architecture.
General Data Protection Regulation (GDPR):
SurePay takes utmost care to adhere to the GDPR (EU) and AVG (NL) principles. As a company which handles your data on a daily basis, the safety of your data and protection of your rights is one of SurePay’s top priorities. Therefore, SurePay commits itself and its affiliates to all applicable data protection.The exercise of your rights is safeguarded by internal policies, and for information on which data we process and why, please check our Privacy Notice on this page.
FAQs
SurePay is ISO 27001 Compliant.
The Statement of Applicability (SOA) is only mandatory for organizations that pursue full certification, therefore, it does not apply to us.
Instead, SurePay has SOC2 type 2 attestation. This attestation demonstrates that our controls are transparent and independently verified, and they are available for review upon request.
- Verified Security: You can have even greater confidence that your data is protected by industry-leading protocols.
- Continuous Improvement: We are continuously updating our policies to protect the integrity and availability of our systems.
- Expanded Oversight: Our reporting now includes additional coverage of Privacy and ESG (Environmental, Social, and Governance) controls along with more and detailed security controls.
Our role (Processor or Controller) depends on the specific service provided and is formally defined in a Data Processing Agreement (DPA).
SurePay will retain your data for 7 years. This is done to enable both you and SurePay to comply with our respective legal obligations.
SurePay and its subprocessors only process personal data within the EEA and UK. Should we be required to transfer data to a third-country, we will apply all safeguards required by the applicable law.
We are happy to provide the extract from the Dutch Chamber of Commerce (KVK), which contains the official information necessary to identify our directors.
For security and privacy reasons we do not supply copies of our directors’ passports to customers. Sharing identity documents broadly creates unnecessary risks, including identity theft which could eventually lead to phishing attacks and other frauds.
If you need copy of the identity documents for a specific compliance purpose, please do reach out to us at any time.
