Skip to main content
Twilio logo

Twilio

PCI DSS evidence

twilio.comCommunications and CPaaSLast verified 17 Sep 2026
PCI DSS mark, CertReports state Verified as of 17 Sep 2026Verified

Twilio and PCI DSS

Twilio is listed in the Visa Global Registry of Service Providers for PCI DSS (Listed on the Visa Global Registry as PCI DSS validated through 2026-12-31), dated 21 Jan 2019, assessed by Coalfire Systems, Inc. CertReports last verified this on 17 Sep 2026 from the registry.

Evidence

VerifiedListed on the Visa Global Registry as PCI DSS validated through 2026-12-31
as of 17 Sep 2026 · confidence 100%
Kind
attestation
Issued or listed
21 Jan 2019
Expires or valid through
31 Dec 2026
Auditor or assessor
Coalfire Systems, Inc
Scope
THIRD PARTY SERVICER, MERCHANT SERVICER - VISA
SourceCapturedQuoteLinks
Visa Global Registry of Service Providers
Official registry · HTTP 200
17 Sep 2026Twilio Inc: PCI DSS, assessor Coalfire Systems, Inc, valid through 2026-12-31
Live pagesha256 3b6dcbf153
Vendor-statedVendor states PCI DSS on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Twilio trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026PCI DSS
Live page Snapshotsha256 dd0c3515b1

What is not public

  • The Visa registry lists the assessor and the date the validation runs through, not the services in scope of the attestation of compliance.
What PCI DSS means, and what it does not

Only a registry listing (Visa Global Registry, Mastercard SDP) or an AOC letter is strong evidence. In the Visa registry only rows validated as PCI DSS with a validation date count; Third Party Agent registrations are not PCI evidence.

Read the PCI DSS guide and browse all vendors with evidence

Questions buyers ask

Is Twilio PCI DSS compliant?

Twilio is listed as a PCI DSS validated service provider, assessed by Coalfire Systems, Inc, valid through 31 Dec 2026, as of 17 Sep 2026.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 17 Sep 2026Subprocessor added: Account Phishing Incident Incidents TwilioAccount Phishing Incident Incidents Twilio appeared on the subprocessor list.
  2. 17 Sep 2026Subprocessor added: CVE Publication TwilioCVE Publication Twilio appeared on the subprocessor list.
  3. 17 Sep 2026Subprocessor added: Does TwilioDoes Twilio appeared on the subprocessor list.

Alternatives with PCI DSS evidence

Similar vendors (shared product tags or the Communications and CPaaS category) whose PCI DSS row is verified or vendor-stated, ranked by similarity.