{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"vesta","name":"Vesta","domain":"vesta.io","category":"Payments","one_liner":"Vesta helps telecom brands approve more payments, reduce fraud losses & grow revenue with specialized payment processing &","trust_center_url":null,"security_page_url":null,"url":"https://certreports.com/vendors/vesta/security","last_verified_at":"2026-09-17T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"pci-dss","framework_name":"PCI DSS","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Visa Global Registry of Service Providers as of 17 Sep 2026.","kind":"attestation","status_text":"Listed on the Visa Global Registry as PCI DSS validated through 2027-06-30","issued_at":"2020-02-28","expires_at":"2027-06-30","period_start":null,"period_end":null,"auditor":"CGI Technologies and Solutions, Inc.","impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"visa_grsp","url":"https://certreports.com/vendors/vesta/pci-dss","evidence":[{"source_type":"registry","source_name":"Visa Global Registry of Service Providers","url":"https://www.visa.com/splisting/","fetched_at":"2026-09-17 15:59:47.031375+00","content_hash":"441e680669917b0c2609744f95fae35f7e8f73048aecc2eb02c13902648751b4","wayback_url":null,"quote":"Vesta Payment Solutions Ltd: PCI DSS, assessor CGI Technologies and Solutions, Inc., valid through 2027-06-30","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: EU-US Certification, SW-US Certification, UK Extension Certification","issued_at":"2016-11-15","expires_at":"2026-11-20","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/vesta/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/4607","fetched_at":"2026-09-17 15:48:34.787376+00","content_hash":"e8337bc08bf58efb0cd5ea5c8d7c3f7df1170508875372f77ec2a5676150481c","wayback_url":null,"quote":"Vesta Corporation: Active: EU-US Certification, SW-US Certification, UK Extension Certification","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, Vesta is listed in the Visa Global Registry as PCI DSS validated, with validation through 30 Jun 2027, per an assessment involving CGI Technologies and Solutions, Inc. As of 17 Sep 2026, Vesta is listed in the EU-US Data Privacy Framework registry with active EU-US Certification, SW-US Certification, and UK Extension Certification status, effective since 15 Nov 2016 and set to expire 20 Nov 2026. No public evidence found for SOC 2 as of 17 Sep 2026. No public evidence found for ISO 27001 as of 17 Sep 2026. No public evidence found for HIPAA as of 17 Sep 2026, so it is unclear whether Vesta offers a BAA.","bullets":["PCI DSS: listed in Visa Global Registry, validated through 30 Jun 2027 (auditor: CGI Technologies and Solutions, Inc.), as of 17 Sep 2026.","EU-US Data Privacy Framework: listed in DPF registry, active certification (EU-US, SW-US, UK Extension), expires 20 Nov 2026, as of 17 Sep 2026.","SOC 2, ISO 27001, and HIPAA: no public evidence found as of 17 Sep 2026."],"model":"claude-sonnet-5","generated_at":"2026-09-17 18:49:19.053432+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T08:09:35.825Z"}