Payment security & compliance
Flywire undergoes an annual SOC II and PCI DSS review to help ensure that Flywire handles customer data securely and in compliance with all applicable laws, including, but not limited to, GDPR, PIPEDA, FERPA, GLBA and other data protection law so you can feel confident in the security of your transactions.
Flywire also maintains robust anti-financial crimes compliance programs as required by our global regulators to ensure our business complies with regulations where we operate.

Security measures we take to protect your payments
Flywire Named to PCI Security Standards Council 2025-2027 Board of Advisors
Flywire has been named to the PCI Security Standards Council 2025-2027 Board of Advisors. Flywire’s Chief Technology Officer David King, and Chief Information Officer / Chief Information Security Officer Barbara Cousins, will represent Flywire on the PCI SSC Board of Advisors and provide their expertise to help shape the future of payment security.
What is Flywire's PCI DSS compliance level?
Flywire maintains PCI Level 1 Certification with third-party attestations—the highest level. This certification is renewed annually.
Does Flywire undergo SOC 2 audits?
Yes. Flywire undergoes an annual SOC 2 Type II audit supporting information management processes. These reports are available upon request for authorized security reviewers and procurement teams.
Which data protection regulations does Flywire comply with?
Flywire is compliant with GDPR (EU), PIPEDA (Canada), FERPA (US education records), GLBA (US financial privacy), HITRUST, and other regional data-protection laws. Flywire also maintains robust anti-financial crimes compliance programs.
What security measures does Flywire implement?
Flywire implements multiple security layers: on-going vulnerability scanning, application firewall, input validation, annual penetration tests, annual SOC II security audits, and annual PCI DSS external reviews.



