Vergo is built on a Security by Design foundation, meaning security is embedded into every layer of the platform — not bolted on after the fact. Whether you're managing corporate card transactions, AP automation, or ERP integrations, your data is protected at every step.
Certifications and compliance
PCI-DSS v4 Level 1 Service Provider — the highest level of certification in the payment card industry, validated through rigorous third-party assessment.
GDPR and CCPA compliant — Vergo adheres to both European and California data privacy regulations, covering how personal data is collected, stored, and processed.
Encryption and authentication
TLS 1.2 / TLS 1.3 encryption — all data transmitted between your systems and Vergo is encrypted in transit using modern TLS protocols.
Encryption at rest — sensitive customer data stored within Vergo is encrypted at rest, providing an additional layer of protection against unauthorized access.
OAuth2 authentication — API access is secured through industry-standard OAuth2, ensuring that only authorized integrations can connect to your data.
Ongoing testing and monitoring
Annual penetration testing — Vergo engages third-party security firms to conduct penetration tests annually, with remediation plans actioned promptly on any findings.
Frequent ASV scans — Approved Scanning Vendor scans are conducted on a regular cadence to detect and address vulnerabilities before they can be exploited.
Continuous vulnerability monitoring — formal policies govern vulnerability management and system monitoring across Vergo's infrastructure.
For a deeper look at Vergo's access controls and organizational security practices, see the related articles in this collection.
