Skip to main content
Decaf logo

Decaf

Security and trust center evidence

Receive, hold, convert, pay suppliers, run disbursements, and automate global money movement through one Decaf Business

decaf.soLast verified 29 Sep 2026

Summary

Decaf has 1 registry-verified row in the CertReports index, last verified 29 Sep 2026. The strongest row is PCI DSS: Listed on the Visa Global Registry as PCI DSS validated through 2026-11-30. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 29 Sep 2026, CertReports holds 1 registry-verified row for Decaf, drawn from the Visa Global Registry. Decaf is listed in the Visa Global Registry of Service Providers for PCI DSS (Listed on the Visa Global Registry as PCI DSS validated through 2026-11-30), dated 5 Apr 2012, assessed by ControlCase, LLC. No public evidence was found for SOC 2, ISO/IEC 27001, HIPAA and GDPR as of 29 Sep 2026; that is a gap in the public record, not a finding of non-coverage, and the vendor can supply it under NDA.

  • PCI DSS: Listed on the Visa Global Registry as PCI DSS validated through 2026-11-30, verified as of 29 Sep 2026

Facts only, each dated; nothing here is inferred, scored or advised.

Evidence count

1verified rows

Compliance grid

No public evidence yet for HIPAA, SOC 2, GDPR, FedRAMP, ISO 27001, CSA STAR, Cyber Essentials, ISO 27701, ISO 42001. This does not mean the vendor lacks them; it means nothing public was found at the last check.

Subprocessors

No subprocessor list captured yet.

Change history

  1. 29 Sep 2026First indexed by CertReports1 evidence row across 1 framework entered the index.

Evidence against regulations

All regulations for Decaf

How much of each regulation’s vendor requirements Decaf’s public evidence reaches.

All articles