Stripe
20 fields evidenced · 39 with no public information. Every value below links to the document it came from and the date we checked it.
9 of those are quoted but not yet interpreted: we hold the source sentence and the date we read it, but nobody has written the answer to the question yet. Those rows show the quote and say so rather than repeating it back as an answer. Why these exist
1 of those is flagged for review: our own check found language in the cited source that may address the field. An editor has not adjudicated it yet.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
"you can assign different detailed roles to enable least-privilege access for your employees, and create restricted API keys" - restricted API keys are a scope limit actually enforced at call time, not merely a described intent. Falls short of 3 because no spend ceiling or authority limit on agent-initiated actions is published on the pages checked. The runtime_governance field previously filed here quoted "Actions within the most sensitive areas of the infrastructure need a human review", which describes Stripe's own internal change management, not a control the customer's agent runs under; it was rejected in this audit.
Is there a tamper-evident record of what it actually did?
"You can also view audit logs of important account changes and activity in your security history" evidences a customer-reviewable record of account activity. Falls short of 3: the only immutability claim on the page ("Code changes are recorded in an immutable, tamper-evident log") is about Stripe's internal code deployment pipeline, not this record, and the field asserting otherwise was rejected in this audit.
This score counts Tamper-evident log as undisclosed, and that absence is flagged for review — the cited source may address it. If so, this score is too low. How we check absences
Are compliance obligations attached per engagement?
"certified us to PCI Service Provider Level 1" is a named certification from a named regime, and the DPA binds Stripe to comply with data protection law when processing personal data. Falls short of 3: PCI DSS is a payments-security regime, not an AI assurance schedule, and no per-engagement compliance schedule or AI framework posture is published.
Does payment depend on a verified result?
No public evidence found. "Integrated per-transaction pricing with no hidden fees" charges per transaction processed, which is a usage fee, not payment released on a verified outcome of agent work.
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
No public evidence found. Neither the security page nor the DPA checked names cover, a carrier, a policy limit, or a customer indemnity for AI or agent-caused loss.
How this gap gets closed →Assurance
- Insurance available
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Own liability cover
- no public informationstripe.com · checked Aug 21, 2026 · source did not state this
- Insurance carriers
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Coverage limits
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Indemnification
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Liability cap
- no public informationstripe.com · checked Aug 14, 2026 · source did not state this
- Audit trail
- User-facing audit logs of account changes/activity
“You can also view audit logs of important account changes and activity in your security history”
stripe.com · checked Aug 14, 2026 - Tamper-evident log
- no public information
Flagged for review — the source below contains language that may address this field. Not yet checked by an editor. How we check absences
stripe.com · checked Aug 14, 2026 - Explainability
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Runtime governance
- no public informationstripe.com · checked Aug 14, 2026 · source did not state this
- Permission scopes
- Dashboard supports assigning detailed least-privilege roles to employees and creating restricted API keys
“you can assign different detailed roles to enable least-privilege access for your employees, and create restricted API keys”
stripe.com · checked Aug 21, 2026 - Compliance certifications
- PCI Service Provider Level 1 certification
“certified us to PCI Service Provider Level 1”
stripe.com · checked Aug 14, 2026 - Regulatory alignment
- Contractually undertakes to comply with data protection law when processing personal data (DPA); no specific statute, AI framework or controller/processor role is named in the span cited
“Stripe must comply with and perform its obligations under DP Law when Processing Personal Data”
stripe.com · checked Aug 14, 2026 - Outcome-based pricing
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Settlement mechanism
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Asset custody
- A dedicated team manages Stripe's Card Data Vault in an isolated AWS environment
“A dedicated team manages our CDV in an isolated Amazon Web Services (AWS) environment”
stripe.com · checked Aug 21, 2026 - Dispute process
- no public informationstripe.com · checked Aug 14, 2026 · source did not state this
- SLA terms
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Evaluation coverage
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Self-reported performance
- no public informationstripe.com · checked Aug 21, 2026 · source did not state this
Agency
- Autonomy level
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Human oversight
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Goal complexity
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Action space
- agent toolkit lets AI agents earn and spend funds on a user's behalf
“The agent toolkit allows your agents to help you earn and spend funds, expanding their capabilities.”
stripe.com · checked Aug 14, 2026 - Operating environment
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Initiative
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
Safety
- Safety evaluations
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Red teaming
- Security teams conduct regular penetration tests and red team exercises against infrastructure
“Our security teams test our infrastructure regularly by scanning for vulnerabilities and conducting penetration tests and red team exercises.”
stripe.com · checked Aug 21, 2026 - Safety policy
- no public informationstripe.com · checked Aug 11, 2026 · source did not state this
- Usage restrictions
- no public informationstripe.com · checked Aug 14, 2026 · source did not state this
- Model or system card
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Incident reporting
- Bug bounty vulnerability contact via HackerOne
“Contact: https://hackerone.com/stripe”
stripe.com · checked Aug 14, 2026 - Third-party evaluations
- Third-party security firms conduct scans/pen tests
“We hire industry-leading security companies to perform third-party scans of our systems”
stripe.com · checked Aug 14, 2026 - Data handling
- AES-256 encryption of production data at rest
“To protect data at rest, Stripe uses industry standard encryption (AES-256) to encrypt all production data stored in server infrastructure.”
stripe.com · checked Aug 14, 2026
Practicality
- Pricing model
“Integrated per-transaction pricing with no hidden fees”
stripe.com · checked Aug 6, 2026- Price point
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Availability
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Deployment options
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Integrations
“Connect to existing systems. Orchestrate payments across multiple processors, build custom workflows, and connect to third parties using APIs, partner apps, or prebuilt integrations.”
stripe.com · checked Aug 6, 2026- Supported regions
“160 countries”
stripe.com · checked Aug 6, 2026- Support model
“Support plans. Receive ongoing assistance and day-to-day support for technical questions with tiered plans based on your needs.”
stripe.com · checked Aug 6, 2026
Foundation models
- Base models
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Model provider
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Model swappable
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Open weights
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Fine-tuning
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Context window
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
Ecosystem
- Protocols supported
“Agentic Commerce Protocol (ACP)”
stripe.com · checked Aug 6, 2026- Tool use
- SDKs, APIs, MCP server, and AI developer tools for integration
“Use our SDKs, APIs, MCP server, and AI developer tools to build and maintain your own integration with Stripe.”
stripe.com · checked Aug 11, 2026 - Multi-agent
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- API access
“500M+ API requests per day”
stripe.com · checked Aug 6, 2026- Open source
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Marketplace presence
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
Impact
- User base
“200M+ active subscriptions managed on Stripe Billing”
stripe.com · checked Aug 6, 2026- Deployment scale
“1.9T in payments volume processed in 2025”
stripe.com · checked Aug 6, 2026- Target sectors
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- High-risk domains
“Accept payments, offer financial services”
stripe.com · checked Aug 6, 2026- Documented incidents
- no public informationstripe.com · checked Aug 6, 2026 · source did not state this
- Market recognition
- no public informationstripe.com · checked Aug 21, 2026 · source did not state this