{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"ramp","name":"Ramp","domain":"ramp.com","category":"Finance and accounting","one_liner":"Make expense management easy with Ramp's spend management","trust_center_url":"https://trust.ramp.com/","security_page_url":null,"url":"https://certreports.com/vendors/ramp/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Drata) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states SOC 2 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"drata","url":"https://certreports.com/vendors/ramp/soc-2","evidence":[{"source_type":"trust_center","source_name":"Ramp trust centre (Drata)","url":"https://trust.ramp.com/","fetched_at":"2026-09-17 16:28:20.066138+00","content_hash":"c50a132ffa9981b5f680fb6f176bcd1c2f868ce6e2695553ba5905fea079ba87","wayback_url":null,"quote":"SOC 2","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 19 Sep 2026.","kind":"listing","status_text":"FedRAMP Ready","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":"Coalfire Systems, Inc.","impact_level":"Moderate","as_of":"2026-09-19","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/ramp/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2516072131","fetched_at":"2026-09-19 08:30:01.700532+00","content_hash":"b2bb3e031fda16f1f3201a5640ae64a639a15e4997f9d1ca43ef13a2942600e6","wayback_url":null,"quote":"Ramp - Ramp for Government (RampGov): FedRAMP Ready","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2516072131","fetched_at":"2026-09-18 22:35:17.44827+00","content_hash":"db2d03fa40cba0e5287b9cc7361e71b7c30c7ca9d51efb7b540477105fb30c7b","wayback_url":null,"quote":"Ramp - Ramp for Government (RampGov): FedRAMP Ready","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2516072131","fetched_at":"2026-09-17 15:44:39.301965+00","content_hash":"395e7ad35dd25d1c547414140161c47ec22827b7ffae3bdbbd5256c38a3b940f","wayback_url":null,"quote":"Ramp - Ramp for Government (RampGov): FedRAMP Ready","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Visa Global Registry of Service Providers as of 17 Sep 2026.","kind":"attestation","status_text":"Listed on the Visa Global Registry as PCI DSS validated through 2026-12-31","issued_at":"2021-07-13","expires_at":"2026-12-31","period_start":null,"period_end":null,"auditor":"Coalfire Systems, Inc","impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"visa_grsp","url":"https://certreports.com/vendors/ramp/pci-dss","evidence":[{"source_type":"registry","source_name":"Visa Global Registry of Service Providers","url":"https://www.visa.com/splisting/","fetched_at":"2026-09-17 15:59:12.070203+00","content_hash":"976e90a650da30405684cede539eb213744d6308b95345aaca403125e8c62213","wayback_url":null,"quote":"Ramp Business Corporation: PCI DSS, assessor Coalfire Systems, Inc, valid through 2026-12-31","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Drata) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states ISO/IEC 27001 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"drata","url":"https://certreports.com/vendors/ramp/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Ramp trust centre (Drata)","url":"https://trust.ramp.com/","fetched_at":"2026-09-17 16:28:20.066138+00","content_hash":"c50a132ffa9981b5f680fb6f176bcd1c2f868ce6e2695553ba5905fea079ba87","wayback_url":null,"quote":"ISO/IEC 27001","confidence":1}]},{"framework":"soc-1","framework_name":"SOC 1","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 1 Type II report on its trust centre (Drata) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states SOC 1 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"drata","url":"https://certreports.com/vendors/ramp/security","evidence":[{"source_type":"trust_center","source_name":"Ramp trust centre (Drata)","url":"https://trust.ramp.com/","fetched_at":"2026-09-17 16:28:20.066138+00","content_hash":"c50a132ffa9981b5f680fb6f176bcd1c2f868ce6e2695553ba5905fea079ba87","wayback_url":null,"quote":"SOC 1","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"expired","state_label":"Expired","sentence":"Certificate expiry unknown date passed; no renewal found as of 17 Sep 2026.","kind":"listing","status_text":"Inactive","issued_at":"2017-11-15","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/ramp/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/8216","fetched_at":"2026-09-17 15:50:28.308043+00","content_hash":"5895e0defb0b7436c3c7c51197cbfced7e8a50f5a64cd0e7c3ed668d132a2a1a","wayback_url":null,"quote":"Ramp Holdings, Inc.: Inactive","confidence":1}]},{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on its trust centre (Drata) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"drata","url":"https://certreports.com/vendors/ramp/security","evidence":[{"source_type":"trust_center","source_name":"Ramp trust centre (Drata)","url":"https://trust.ramp.com/","fetched_at":"2026-09-17 16:28:20.066138+00","content_hash":"c50a132ffa9981b5f680fb6f176bcd1c2f868ce6e2695553ba5905fea079ba87","wayback_url":null,"quote":"CCPA","confidence":1}]},{"framework":"govramp","framework_name":"GovRAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an GovRAMP authorization on its trust centre (Drata) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states GovRAMP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"drata","url":"https://certreports.com/vendors/ramp/security","evidence":[{"source_type":"trust_center","source_name":"Ramp trust centre (Drata)","url":"https://trust.ramp.com/","fetched_at":"2026-09-17 16:28:20.066138+00","content_hash":"c50a132ffa9981b5f680fb6f176bcd1c2f868ce6e2695553ba5905fea079ba87","wayback_url":null,"quote":"GovRAMP","confidence":1}]},{"framework":"txramp","framework_name":"TX-RAMP","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an TX-RAMP certification on its trust centre (Drata) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states TX-RAMP on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"drata","url":"https://certreports.com/vendors/ramp/security","evidence":[{"source_type":"trust_center","source_name":"Ramp trust centre (Drata)","url":"https://trust.ramp.com/","fetched_at":"2026-09-17 16:28:20.066138+00","content_hash":"c50a132ffa9981b5f680fb6f176bcd1c2f868ce6e2695553ba5905fea079ba87","wayback_url":null,"quote":"TX-RAMP","confidence":1}]},{"framework":"cyber-essentials-plus","framework_name":"Cyber Essentials Plus","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an Cyber Essentials Plus certificate on its trust centre (Drata) as of 17 Sep 2026.","kind":null,"status_text":"Vendor states Cyber Essentials Plus on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"drata","url":"https://certreports.com/vendors/ramp/security","evidence":[{"source_type":"trust_center","source_name":"Ramp trust centre (Drata)","url":"https://trust.ramp.com/","fetched_at":"2026-09-17 16:28:20.066138+00","content_hash":"c50a132ffa9981b5f680fb6f176bcd1c2f868ce6e2695553ba5905fea079ba87","wayback_url":null,"quote":"Cyber Essentials Plus","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, Ramp states on its trust centre that it holds SOC 2, SOC 1 and ISO/IEC 27001. As of 17 Sep 2026, Ramp states on its trust centre that it holds CCPA/CPRA, GovRAMP, TX-RAMP and Cyber Essentials Plus. As of 19 Sep 2026, Ramp is listed in the FedRAMP registry as FedRAMP Ready, audited by Coalfire Systems, Inc. As of 17 Sep 2026, Ramp is listed on the Visa Global Registry as PCI DSS validated through 31 Dec 2026, issued 13 Jul 2021 and audited by Coalfire Systems, Inc. As of 17 Sep 2026, Ramp's EU-US Data Privacy Framework registry entry showed an inactive status, with certification originally issued 15 Nov 2017.","bullets":["Vendor-stated (trust centre, as of 17 Sep 2026): SOC 2, SOC 1, ISO/IEC 27001, CCPA/CPRA, GovRAMP, TX-RAMP, Cyber Essentials Plus.","Registry-verified: FedRAMP Ready (as of 19 Sep 2026, auditor Coalfire Systems, Inc.); PCI DSS validated through 31 Dec 2026 on the Visa Global Registry (as of 17 Sep 2026, auditor Coalfire Systems, Inc.).","EU-US Data Privacy Framework: expired, originally issued 15 Nov 2017 (as of 17 Sep 2026)."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 11:25:37.795499+00"},"legal_docs":[{"kind":"subprocessors","url":"https://trust.ramp.com/","availability":"public","detail":"6 subprocessors listed on the trust centre","as_of":"2026-09-17"}],"subprocessors":[{"name":"Amplitude Inc","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Duffel Technology Ltd","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Security Infrastructure Amazon Web Services","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Sierra Technologies Inc","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"Sign in with Google IdP flow. The fake Google","domain":null,"purpose":null,"location":null,"vendor_url":null},{"name":"The phishing campaign also targets Google","domain":null,"purpose":null,"location":null,"vendor_url":null}],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-20T06:07:57.404Z"}