Skip to main content

How Vergo keeps your card and payment data secure

An overview of Vergo's core security certifications and compliance standards — PCI-DSS v4 Level 1, TLS encryption, OAuth2 authentication, GDPR, and CCPA.

Vergo is built on a Security by Design foundation, meaning security is embedded into every layer of the platform — not bolted on after the fact. Whether you're managing corporate card transactions, AP automation, or ERP integrations, your data is protected at every step.

Certifications and compliance

  • PCI-DSS v4 Level 1 Service Provider — the highest level of certification in the payment card industry, validated through rigorous third-party assessment.

  • GDPR and CCPA compliant — Vergo adheres to both European and California data privacy regulations, covering how personal data is collected, stored, and processed.

Encryption and authentication

  • TLS 1.2 / TLS 1.3 encryption — all data transmitted between your systems and Vergo is encrypted in transit using modern TLS protocols.

  • Encryption at rest — sensitive customer data stored within Vergo is encrypted at rest, providing an additional layer of protection against unauthorized access.

  • OAuth2 authentication — API access is secured through industry-standard OAuth2, ensuring that only authorized integrations can connect to your data.

Ongoing testing and monitoring

  • Annual penetration testing — Vergo engages third-party security firms to conduct penetration tests annually, with remediation plans actioned promptly on any findings.

  • Frequent ASV scans — Approved Scanning Vendor scans are conducted on a regular cadence to detect and address vulnerabilities before they can be exploited.

  • Continuous vulnerability monitoring — formal policies govern vulnerability management and system monitoring across Vergo's infrastructure.

For a deeper look at Vergo's access controls and organizational security practices, see the related articles in this collection.

Did this answer your question?