MoonPay Achieves 2026 SOC 2 Type 2 Certification
The 2026 audit adds Privacy to our Trust Services Criteria and brings three more platforms into scope.
By Team MoonPay
Published on Aug 4, 2026
Last modified on Aug 4, 2026

We're pleased to announce that MoonPay has successfully completed its 2026 SOC 2 Type 2 annual recertification with a clean opinion. The result, which is the strongest an independent auditor can issue, confirms that MoonPay's controls were not just well-designed, but operated effectively throughout the review period.
SOC 2 Type 2 is one of the most widely respected benchmarks in information security. Unlike a Type 1 audit, which checks that controls are designed properly at a single point in time, Type 2 evaluates whether those controls actually hold up over months of real operation. It’s a higher bar, and a better signal of how a company handles data day to day.
This year, we also added Privacy as a new Trust Services Criteria category, bringing our SOC 2 Type 2 coverage to four of the five criteria defined by the AICPA: Security, Availability, Confidentiality, and Privacy. The fifth, Processing Integrity, mainly applies to companies processing transactions on behalf of others and sits outside our current scope. The addition of Privacy reflects how much personal and financial data now flows through MoonPay on behalf of our customers and partners, and it gives them one more independent benchmark to point to in their own vendor reviews.
This audit cycle also brought three more products fully into scope: ,, and . That means the same independently verified security and privacy standard we hold our core ramp business to now extends across a bigger share of the MoonPay product suite.