MoonPay Achieves 2026 SOC 2 Type 2 Certification
The 2026 audit adds Privacy to our Trust Services Criteria and brings three more platforms into scope.
By Team MoonPay
Published on Aug 4, 2026
Last modified on Aug 4, 2026
.png)
We're pleased to announce that MoonPay has successfully completed its 2026 SOC 2 Type 2 annual recertification with a clean opinion. The result, which is the strongest an independent auditor can issue, confirms that MoonPay's controls were not just well-designed, but operated effectively throughout the review period.
SOC 2 Type 2 is one of the most widely respected benchmarks in information security. Unlike a Type 1 audit, which checks that controls are designed properly at a single point in time, Type 2 evaluates whether those controls actually hold up over months of real operation. It’s a higher bar, and a better signal of how a company handles data day to day.
This year, we also added Privacy as a new Trust Services Criteria category, bringing our SOC 2 Type 2 coverage to four of the five criteria defined by the AICPA: Security, Availability, Confidentiality, and Privacy. The fifth, Processing Integrity, mainly applies to companies processing transactions on behalf of others and sits outside our current scope. The addition of Privacy reflects how much personal and financial data now flows through MoonPay on behalf of our customers and partners, and it gives them one more independent benchmark to point to in their own vendor reviews.
This audit cycle also brought three more products fully into scope: Virtual Accounts, MoonPay Trade, and MoonPay Commerce. That means the same independently verified security and privacy standard we hold our core ramp business to now extends across a bigger share of the MoonPay product suite.
"Adding Privacy to our SOC 2 Type 2 scope reflects how seriously we take the responsibility that comes with handling sensitive data at scale," said Doug Innocenti, Chief Information Officer and Chief Security Officer at MoonPay. "For our customers and partners, this report is a way to independently verify that commitment rather than take our word for it, and it's a standard we intend to keep raising as our platform grows."
This builds on the SOC 2 Type 2 certification MoonPay first earned in 2024, alongside our ISO 27001, 27018, 27701 and PCI DSS certifications. As MoonPay continues integrating the businesses we've acquired, we expect to bring those newly integrated platforms into SOC 2 Type 2 scope in future audit cycles too.
Information security is core to how we operate, and we're confident this expanded certification will help us build even greater trust with the customers and partners who rely on us.