{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"fintoc","name":"Fintoc","domain":"fintoc.com","category":"Developer tools","one_liner":"Account-to-Account payments in Mexico and Chile.","trust_center_url":"https://compliance.fintoc.com/","security_page_url":null,"url":"https://certreports.com/vendors/fintoc/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"pci-dss","framework_name":"PCI DSS","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a PCI DSS attestation of compliance on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states PCI DSS 4.0.1 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/fintoc/pci-dss","evidence":[{"source_type":"trust_center","source_name":"Fintoc trust centre (Vanta)","url":"https://compliance.fintoc.com/","fetched_at":"2026-09-18 23:18:30.309109+00","content_hash":"5a6e489bc5caa616ad5d31871d6b01ab7c0bd93754470299abd73cf342e57c80","wayback_url":null,"quote":"PCI DSS 4.0.1","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/fintoc/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Fintoc trust centre (Vanta)","url":"https://compliance.fintoc.com/","fetched_at":"2026-09-18 23:18:30.309109+00","content_hash":"5a6e489bc5caa616ad5d31871d6b01ab7c0bd93754470299abd73cf342e57c80","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]}],"brief":null,"legal_docs":[{"kind":"subprocessors","url":"https://compliance.fintoc.com/","availability":"public","detail":"2 subprocessors listed on the trust centre","as_of":"2026-09-18"}],"subprocessors":[{"name":"Cloudflare","domain":"cloudflare.com","purpose":"Traffic Routing & CDN","location":"Global","vendor_url":"https://certreports.com/vendors/cloudflare/security"},{"name":"Google Cloud Platform","domain":"google.com","purpose":"Cloud infrastructure","location":"United States","vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T10:52:36.033Z"}