DOI : 10.17577/A fintech startup in Bengaluru picked a payment gateway without checking its compliance status. Three months and 10,000 transactions later, their acquiring bank flagged them. The payment gateway had not completed the PCI DSS v4.0 transition on time. Remediation cost four weeks and Rs 3.2 lakh in emergency audit fees. No data was stolen. The payment gateway simply had not kept up with the compliance calendar.
Most payment gateway comparisons focus on pricing and features. This guide compares Razorpay, Cashfree, PayU, and Stripe on what actually protects your business: security certifications, RBI data localisation compliance, fraud prevention infrastructure, and data protection practices. All claims are based on publicly available certification documents and independently verifiable security documentation as of September 2026.
Key Takeaways: Payment Gateway Security Comparison at a Glance
- Razorpay holds the widest compliance certification portfolio among Indian payment gateways, with PCI DSS v4.0 Level 1 across five separate entities, ISO 27001 across five entities, SOC 2 and SOC 3 reports, and independently audited RBI data localisation compliance across five entities. No other Indian payment gateway publishes this breadth of entity-level certification coverage.
- All four payment gateways, Razorpay, Cashfree, PayU, and Stripe, hold PCI DSS Level 1 certification, the highest tier available. The difference is in version currency, scope of coverage, and the number of subsidiary entities independently certified.
- Razorpay is the only Indian payment gateway that publishes downloadable certificates of compliance (COC) for every entity and every certification category directly on its Trust Portal (razorpay.com/security/certifications). Cashfree publishes PCI DSS and ISO certificates as PDF links. PayU and Stripe reference their certification status but do not offer the same level of public certificate access for their India operations.
- RBI data localisation is a hard regulatory requirement in India since 2018. Razorpay publishes third-party audited data localisation reports for five entities. Cashfree, PayU, and Stripe do not publish comparable public documentation for data localisation compliance specific to their India operations.
- Razorpay operates a dedicated Trust Portal with a threat intelligence dashboard powered by CloudSEK, offering real-time visibility into global attack vectors and verified threat feeds. No other payment gateway on this list operates an equivalent public-facing security intelligence centre.
- Stripe’s global security infrastructure is the most mature across international markets, with NIST Cybersecurity Framework alignment, CBPR/PRP privacy certifications, and EMVCo Level 1 and 2 terminal certification. For businesses operating primarily in India, however, Stripe’s India-specific compliance documentation is thinner than Razorpay’s.
Why Payment Gateway Security Matters More Than Pricing
Every payment gateway in India charges between 1.5% and 2% for standard domestic transactions. That gap, at best a few hundred rupees per lakh of GMV, is trivial compared to the cost of a single compliance failure.
The real numbers tell the story:
- CERT-In’s 2025 annual report recorded over 16 lakh cybersecurity incidents across Indian organisations, with financial services among the top three targeted sectors
- The average cost of a data breach in India crossed Rs 19.5 crore in 2025, according to IBM’s Cost of a Data Breach report
- RBI’s penalties for non-compliance with data localisation norms have ranged from Rs 1 crore to Rs 5 crore per incident in recent enforcement actions
When a business selects a payment gateway, the security and compliance infrastructure of that provider becomes the business’s own compliance posture:
- If the payment gateway is not PCI DSS v4.0 compliant, the merchant is not compliant
- If the payment gateway stores card data outside India, the merchant is violating RBI directives
- If the payment gateway lacks adequate fraud prevention, the merchant absorbs the chargebacks
The right question is not “which payment gateway charges the lowest fee?” It is “which payment gateway makes my compliance posture strongest from day one?”
What This Guide Evaluates
|
Criterion |
Why It Matters |
|
PCI DSS Certification |
The global standard for payment card data security. Level 1 is the highest tier. Version currency (v4.0 vs v3.2.1) matters because older versions have known gaps that v4.0 addresses. |
|
ISO Certifications |
ISO 27001 (information security management), ISO 27017 (cloud security), ISO 27018 (PII protection in cloud), and ISO 9001 (quality management) demonstrate systematic security governance. |
|
SOC Reports |
SOC 1 and SOC 2 Type II reports verify internal controls over financial reporting, security, availability, and confidentiality through independent third-party audits. |
|
RBI Data Localisation |
Since 2018, the RBI mandates that all payment data for transactions processed in India must be stored exclusively within India. Non-compliance is a regulatory violation, not a best practice. |
|
Fraud Prevention Technology |
ML-based fraud detection, device fingerprinting, risk scoring, and real-time monitoring capabilities determine how well the payment gateway protects against transaction-level threats. |
|
Encryption and Data Handling |
How the payment gateway encrypts card data in transit and at rest, tokenisation implementation, and key management practices. |
|
Vulnerability Management |
Bug bounty programmes, penetration testing frequency, responsible disclosure policies, and proactive threat monitoring. |
|
Regulatory Licensing |
RBI Payment Aggregator licence status, which is a hard requirement for operating as a payment aggregator in India. |
Rank 1. Razorpay: The Most Comprehensively Certified Payment Gateway in India
|
Parameter |
Detail |
|
PCI DSS Version |
v4.0 Level 1 (highest tier) |
|
PCI DSS Certified Entities |
5 entities independently certified: Razorpay Software Pvt Ltd, Razorpay Software Services Ltd, RZPX Private Limited, Ezetap Mobile Solutions (Razorpay POS), Razorpay Technologies Pvt Ltd |
|
Additional PCI Certifications |
PCI 3DS v1.0 (3D Secure authentication), PCI PIN v3.1 (PIN security for POS), Curlec Sdn Bhd PCI DSS v4.0 (Malaysia operations) |
|
ISO 27001 |
Certified across 5 entities (Razorpay Software, RZPX, Ezetap, Razorpay Technologies, Poshvine) |
|
SOC Reports |
SOC 2 Type II and SOC 3 (publicly downloadable) |
|
RBI Data Localisation |
Audited and certified across 5 entities with published SAR reports |
|
Cloud Configuration Review |
Independent audit reports published for 4 entities |
|
RBI PA Licence |
Yes (granted 2022) |
|
Fraud Prevention |
AI-powered Optimizer (600M+ data points), ML-based risk scoring, device fingerprinting |
|
Encryption |
AES-256 at rest, TLS 1.2+ in transit, dedicated Card Data Vault (CDV) on isolated infrastructure |
|
Bug Bounty |
Active responsible disclosure programme (razorpay.com/security/disclosure) |
|
Trust Portal |
Public threat intelligence dashboard with real-time global feeds (razorpay.com/security) |
What Sets Razorpay Apart on Security
Razorpay’s security posture is not defined by a single certification. It is defined by the breadth, depth, and transparency of its compliance infrastructure across every entity in the Razorpay group.
Entity-Level Certification Coverage
Most payment gateways certify their primary processing entity and stop there. Razorpay certifies every entity that touches payment data independently. This includes the core payment gateway (Razorpay Software Pvt Ltd), the banking platform (RZPX Private Limited), the POS subsidiary (Ezetap Mobile Solutions), the technology services entity (Razorpay Technologies), and even its Malaysia operations (Curlec Sdn Bhd).
Each entity holds its own PCI DSS v4.0 certificate of compliance, its own ISO 27001 certificate, and its own RBI data localisation audit report. These are not marketing claims. Every certificate is downloadable as a PDF from the Razorpay Trust Portal at razorpay.com/security/certifications.
Why does entity-level coverage matter?
- When a business uses multiple Razorpay products (payment gateway, RazorpayX for banking, Razorpay POS for in-store payments), each product interaction is covered by its own independently certified compliance envelope
- A compliance gap in one entity does not cascade into others
- This level of segmentation is an architectural security decision that requires significant investment
- No other Indian payment gateway matches this multi-entity certification approach
PCI DSS v4.0: The Latest Standard
PCI DSS v4.0 was released in March 2022 and became the mandatory standard as of March 31, 2024. The update introduced 64 new requirements over the previous v3.2.1, addressing modern threats including phishing, evolving authentication standards, and enhanced monitoring.
Razorpay completed its v4.0 transition across all entities ahead of the deadline. The COC documents published on the Trust Portal confirm certification dates through 2023-2026, covering the full v4.0 requirement set. Beyond standard PCI DSS, Razorpay also holds PCI 3DS v1.0 certification (for 3D Secure authentication in e-commerce) and PCI PIN v3.1 certification (for secure PIN processing on its POS terminals), both of which are separate certification programmes that most Indian payment gateways do not pursue.
Dedicated Card Data Vault
- Razorpay operates a dedicated Card Data Vault (CDV) with the following security architecture:
- Runs on isolated AWS infrastructure, completely separated from the rest of Razorpay’s services
- Encrypts all primary account numbers (PANs) with AES-256 encryption at rest
- Stores decryption keys on separate machines from the encrypted data
- Tokenises card numbers internally so that no other Razorpay service or daemon can access plain-text card data
Key architectural distinctions of the Card Data Vault:
- Not a shared database with an encryption layer on top
- Physically separated infrastructure with its own access controls and its own credential set
- Managed by a restricted team of specially trained engineers
- Access is reviewed quarterly
- Even if Razorpay’s main API infrastructure were compromised, card data would remain isolated and inaccessible
Trust Portal and Threat Intelligence
Razorpay operates a public Trust Portal at razorpay.com/security that goes beyond standard compliance documentation. The portal includes:
- Real-time threat intelligence dashboard powered by CloudSEK
- Global attack vector analysis and verified intelligence feeds
- Research tracker feeds from underground sources
- Operational security tool for merchants and compliance teams, not a marketing page
- Provides visibility into the threat landscape affecting the payments industry
The Trust Portal also includes a merchant security checklist at razorpay.com/security/checklist, helping businesses strengthen their own security posture when integrating with Razorpay.
Fraud Prevention: AI-Powered at Scale
Razorpay Optimizer is an ML engine trained on over 600 million data points from transactions processed across its platform. It routes each payment through the bank or network with the highest approval probability, using five strategies: Smart Routing, Priority Routing, Rule-Based Routing, Custom Identifiers, and Cascading Payments (automatic retry through a backup route if the primary declines).
The fraud prevention layer operates in real time, scoring transactions for risk indicators including device fingerprinting, behavioural analysis, velocity checks, and geographic anomaly detection. Merchants report a 10%+ improvement in payment success rates within weeks of enabling Optimizer, which is itself a security metric, because higher approval rates with lower fraud rates indicate more accurate risk assessment.
Razorpay Is Best For
Businesses of any size that need the strongest verifiable compliance posture in India, particularly those in regulated industries (fintech, insurance, healthcare, education) where demonstrating multi-entity, multi-certification compliance to auditors, banks, and regulators is a business requirement. The combination of entity-level PCI DSS v4.0, ISO 27001, audited data localisation, SOC reports, and a public Trust Portal with real-time threat intelligence is unmatched by any other Indian payment gateway.
Rank 2. Stripe: Best Security Infrastructure for Cross-Border and Global Payments
|
Parameter |
Detail |
|
PCI DSS Version |
Level 1 (PCI Service Provider Level 1, validated by PCI-certified auditor) |
|
PCI DSS Certified Entities |
Stripe Inc. (global entity, India operations covered under global certification) |
|
ISO Certifications |
Not separately published for India |
|
SOC Reports |
SOC 1 Type II, SOC 2 Type II, SOC 3 (publicly downloadable) |
|
NIST |
Aligned with NIST Cybersecurity Framework |
|
Privacy Certifications |
CBPR, PRP, US Data Privacy Framework (EU-US DPF, UK Extension, Swiss-US) |
|
EMVCo |
Level 1 and Level 2 certified terminals (Stripe Terminal) |
|
RBI Data Localisation |
Not publicly documented with India-specific audit reports |
|
RBI PA Licence |
Yes |
|
Fraud Prevention |
Radar (ML-based, trained on data from millions of businesses globally) |
|
Encryption |
AES-256, dedicated Card Data Vault on isolated AWS infrastructure, mTLS internal communication, HSTS, TLS 1.2+ enforced |
|
Bug Bounty |
Active programme on HackerOne |
|
Trust Portal |
Comprehensive security documentation at docs.stripe.com/security |
What Stripe Does Well
Stripe is PCI Service Provider Level 1 certified, validated by a PCI-certified auditor, the most stringent certification available. Beyond PCI DSS, Stripe holds SOC 1 and SOC 2 Type II reports (annual), a publicly downloadable SOC 3 report, EMVCo Level 1 and Level 2 terminal certifications, and alignment with the NIST Cybersecurity Framework.
Privacy and Cross-Border Data Protection
Stripe holds CBPR (Cross-Border Privacy Rules) and PRP (Privacy Recognition for Processors) certifications through TrustArc, plus EU-US DPF, UK Extension, and Swiss-US Data Privacy Framework certifications. For businesses handling cross-border transactions with customers in the EU, UK, or Switzerland, these certifications address data transfer compliance requirements that no Indian payment gateway currently matches.
Card Data Vault and Encryption
The Card Data Vault architecture mirrors Razorpay’s isolated approach with dedicated AWS infrastructure separate from Stripe’s main services, AES-256 encryption at rest, separate decryption key machines, internal tokenisation, and a restricted engineering team with quarterly access reviews. All internal server-to-server communication uses mutual TLS (mTLS), and the stripe.com domain is on Chrome’s top domains list for additional protection against homoglyph phishing attacks.
Fraud Prevention: Radar
Stripe Radar is trained on data from millions of businesses across Stripe’s global network, giving it cross-border fraud pattern detection capabilities that country-specific payment gateways cannot replicate. The ML models improve continuously as Stripe’s global transaction volume grows.
Vulnerability Management
The bug bounty programme on HackerOne provides continuous external security testing by independent researchers. Stripe also proactively scans the internet for leaked merchant API keys and works with Google Safe Browsing to take down phishing pages targeting Stripe users.
Limitations of Stripe
Stripe’s India-specific compliance documentation has gaps. The PCI DSS certification covers Stripe Inc. globally, but there are no separately published India-entity certificates, ISO 27001 reports for India, or RBI data localisation audit reports. For businesses that need to demonstrate India-specific compliance to regulators, banks, or auditors, the global certification approach may require additional documentation requests to Stripe’s compliance team.
Data localisation is a particular concern. Stripe’s global infrastructure processes transactions across multiple data centres worldwide. While Stripe states compliance with local regulations, the absence of published India-specific data localisation audit reports (comparable to Razorpay’s five-entity SAR reports) creates a documentation gap for merchants operating under RBI’s 2018 directive.
Stripe’s India product set is a subset of its global offering. Not all features, including some security-adjacent tools like Stripe Identity for KYC verification, are available in India. The domestic payment method coverage is narrower than Razorpay’s or Cashfree’s, which has implications for security coverage across all payment types a merchant might accept.
Stripe Is Best For
Startups with significant cross-border operations that need privacy certifications (CBPR, PRP, DPF) and global fraud detection capabilities. Stripe’s security infrastructure is world-class for international payment flows. For primarily domestic Indian operations, the India-specific compliance documentation gap and narrower local feature set mean other payment gateways on this list offer more readily demonstrable compliance.
Rank 3. PayU: Established Player with Standard Compliance
|
Parameter |
Detail |
|
PCI DSS Version |
v4.0 Level 1 |
|
PCI DSS Certified Entities |
PayU India entity (specific entity count for India not publicly documented) |
|
ISO Certifications |
ISO 27001:2013 certified (Publicly documented for PayU India and PayU Finance). |
|
SOC Reports |
Not publicly documented for India operations |
|
RBI Data Localisation |
Compliant (mandatory for retaining the RBI PA License), but individual audit reports are not publicly downloadable. |
|
RBI PA Licence |
Yes |
|
Fraud Prevention |
Anti-fraud module with tokenisation and 3D Secure |
|
Encryption |
Tokenisation (universal tokens), PCI-compliant token vault |
|
Bug Bounty |
Not publicly documented |
|
Trust Portal |
No dedicated security portal for India operations |
What PayU Does Well
PayU is a PCI DSS Level 1 certified payment processor serving over 4.5 lakh businesses since 2011. PCI compliance documentation is published through its global corporate site (corporate.payu.com), with Attestation of Compliance (AOC) documents available.
Tokenisation
PayU’s tokenisation implementation uses universal tokens that allow merchants to process card payments across the PayU network without storing or transmitting card data through their own systems. The token vault is PCI-compliant, and tokenisation is the primary mechanism for reducing merchant PCI scope, effectively minimising the merchant’s responsibility for card data security.
Authentication and Fraud Prevention
3D Secure 2.0 is integrated into PayU’s payment flow, providing real-time transaction authentication with risk-based challenge decisions. The anti-fraud module handles risk scoring and transaction monitoring.
Limitations of PayU
PayU’s India-specific security documentation is notably thinner than Razorpay’s and Cashfree’s. The corporate.payu.com site focuses on PCI DSS compliance and tokenisation but does not publish ISO 27001, SOC 2, or RBI data localisation audit reports for the India entity. PayU may hold these certifications internally, but the lack of public documentation means merchants cannot independently verify compliance breadth without direct engagement with PayU’s compliance team.
There is no dedicated security portal or threat intelligence dashboard for the India market. Security information is distributed across the corporate site rather than consolidated in a single auditable location.
The anti-fraud capabilities, while functional, are described in general terms. There is no equivalent to Razorpay’s Optimizer with its 600M+ data point ML model or Cashfree’s RiskShield with government database integration. Published documentation does not specify real-time risk scoring, device fingerprinting, or behavioural analysis capabilities for the India product.
PayU Is Best For
Established businesses already in the PayU ecosystem that need standard PCI DSS Level 1 compliance and effective tokenisation for card-on-file use cases. PayU’s 15-year track record in India provides operational stability, and the LazyPay BNPL integration at checkout is a unique commercial advantage. For compliance-heavy industries requiring detailed multi-certification documentation, merchants should request PayU’s internal compliance portfolio directly.
Rank 4. Cashfree: Single-Entity Certification with Documentation Gaps
|
Parameter |
Detail |
|
PCI DSS Version |
v4.0.1 Level 1 |
|
PCI DSS Certified Entities |
1 entity (Cashfree Payments India Pvt Ltd) |
|
ISO Certifications |
ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, ISO 9001:2015 |
|
SOC Reports |
Not publicly documented |
|
RBI Data Localisation |
Not publicly documented with downloadable audit reports |
|
RBI PA Licence |
Yes |
|
Fraud Prevention |
RiskShield (AI/ML-based, analyses 1M+ data points) |
|
Encryption |
Tokenisation, 3D Secure 2.0, HMAC SHA-256 webhook verification |
|
Bug Bounty |
Not publicly documented |
|
Trust Portal |
Security documentation at cashfree.com/docs/security (no dedicated threat intelligence dashboard) |
What Cashfree Offers
Cashfree holds PCI DSS v4.0.1 Level 1 certification and four ISO certifications including ISO 27017 (cloud security) and ISO 27018 (PII protection in cloud). RiskShield provides AI/ML-based fraud prevention with Government of India database integration.
Limitations of Cashfree
- Certifies only a single entity (Cashfree Payments India Pvt Ltd) for PCI DSS, compared to Razorpay’s five-entity coverage. No compliance segmentation across products.
- RBI data localisation compliance is not publicly documented with downloadable third-party audit reports. Merchants cannot independently verify this to auditors without requesting documentation directly from Cashfree.
- RBI imposed a monetary penalty of Rs 3.10 lakh on Cashfree Payments in March 2026 for non-compliance with Payment Aggregator norms, specifically for making impermissible debits from the escrow account. This is a regulatory red flag for compliance-sensitive businesses.
- No dedicated Trust Portal or threat intelligence dashboard. Security documentation lives within developer docs without real-time threat visibility.
- No publicly documented bug bounty or responsible disclosure programme.
- No published SOC 3 report which is not publicly downloadable without requesting it.
- No published cloud configuration review audits or RBI data localisation SAR reports for independent verification.
Best For
Early-stage startups with basic compliance requirements that need cloud-specific ISO certifications (27017, 27018) and government fraud database integration through RiskShield. Not recommended for regulated industries or businesses that need to demonstrate multi-entity certification coverage to auditors, banks, or regulators.
Side-by-Side: Payment Gateway Security Comparison
|
Feature |
Razorpay |
Stripe |
PayU |
Cashfree |
|
PCI DSS Version |
v4.0 Level 1 |
Level 1 Service Provider |
v4.0 Level 1 |
v4.0.1 Level 1 |
|
PCI DSS Certified Entities (India) |
5 entities |
Global entity |
PayU India (single entity) |
1 entity |
|
Additional PCI Certifications |
PCI 3DS v1.0, PCI PIN v3.1 |
EMVCo Level 1 and 2, PA-DSS |
None publicly documented |
None publicly documented |
|
ISO 27001 |
Yes (5 entities) |
Not separately published for India |
Yes (ISO 27001:2013) |
Yes (ISO 27001:2022) |
|
ISO 27017 (Cloud Security) |
Yes |
Not separately published |
Not publicly documented |
Yes |
|
ISO 27018 (PII in Cloud) |
Yes |
Not separately published |
Not publicly documented |
Yes |
|
SOC 1 Type II |
Not listed |
Yes |
Yes |
Not publicly documented |
|
SOC 2 Type II |
Yes |
Yes |
Not publicly documented |
Not publicly documented |
|
SOC 3 (Public) |
Yes (downloadable) |
Yes (downloadable) |
Not publicly documented |
Not published |
|
RBI Data Localisation Audit |
Published for 5 entities (SAR reports) |
Not publicly published |
Not publicly published |
Not publicly published |
|
RBI PA Licence |
Yes (2022) |
Yes |
Yes |
Yes |
|
Cloud Config Audit |
Published for 4 entities |
Not published |
Not published |
Not published |
|
EMVCo Terminal Certification |
Yes (via Ezetap PCI PIN v3.1) |
Yes (Level 1 and 2) |
No |
No |
|
Fraud Prevention AI/ML |
Optimizer (600M+ data points) |
Radar (global ML model) |
Anti-fraud module |
RiskShield (1M+ data points per txn) |
|
Card Data Vault (Isolated) |
Yes (separate AWS infrastructure) |
Yes (separate AWS infrastructure) |
Token vault (PCI-compliant) |
Not publicly detailed |
|
Encryption at Rest |
AES-256 |
AES-256 |
Not publicly specified |
Not publicly specified |
|
Internal Communication Security |
mTLS via Istio Service Mesh |
mTLS (mutual TLS) |
Not publicly detailed |
HMAC SHA-256 webhooks |
|
Bug Bounty Programme |
Yes (responsible disclosure page) |
Yes (HackerOne) |
Not publicly documented |
Not publicly documented |
|
Public Trust Portal |
Yes (CloudSEK threat intelligence) |
docs.stripe.com/security |
payu.in/cyber-security |
Docs within developer docs |
|
Downloadable Certificates |
All categories (PDF on Trust Portal) |
SOC 3 (PDF) |
Not publicly available |
PCI DSS and ISO (PDF) |
|
Total Certs Publicly Verifiable |
25+ across 5 entities |
8+ (global) |
3 (PCI DSS, ISO 27001, SOC 1) |
7 (PCI DSS, 4 ISOs, SOC 2) |
Which Business Should Pick Which Payment Gateway for Security
|
Business Profile |
Recommended Payment Gateway |
Reasoning |
|
Regulated fintech requiring multi-entity certification evidence |
Razorpay |
Five-entity PCI DSS v4.0, ISO 27001, and RBI data localisation audit coverage provides the most comprehensive compliance documentation for regulatory submissions |
|
Early-stage startup needing fast, compliant setup |
Razorpay |
Broadest out-of-the-box compliance coverage with zero setup fee. Trust Portal and merchant security checklist reduce compliance overhead from day one |
|
API-first business with cloud security requirements |
Razorpay or Cashfree |
Razorpay leads on certification breadth (five-entity PCI DSS v4.0, ISO 27001, SOC 2/3, isolated Card Data Vault). Cashfree adds cloud-specific ISO 27017 and ISO 27018 certifications with government fraud database integration. |
|
D2C brand processing primarily domestic transactions |
Razorpay |
Highest entity-level certification coverage for India, AI-powered fraud prevention trained on 600M+ Indian transaction data points, and published data localisation compliance |
|
Cross-border SaaS with EU/UK customers |
Razorpay or Stripe |
Razorpay supports 130 currencies, international cards at 3%, bank transfers at 1%, five-entity PCI DSS v4.0, and audited RBI data localisation for seamless India-to-global payment flows. Stripe adds CBPR, PRP, and Data Privacy Framework certifications with Radar’s global fraud ML for EU/UK-specific compliance. |
|
Enterprise with existing PayU integration |
PayU |
PCI DSS Level 1 and operational tokenisation are solid. Request PayU’s internal compliance portfolio for ISO and data localisation evidence if needed for audits |
|
Healthcare or education platform handling sensitive data |
Razorpay |
Multi-entity certification segmentation means each Razorpay product used operates under its own independently certified compliance envelope, reducing cross-product risk exposure |
|
Business requiring terminal/POS security certification |
Razorpay or Stripe |
Razorpay (via Ezetap): PCI DSS v4.0, PCI PIN v3.1, EMVCo standards. Stripe Terminal: EMVCo Level 1 and 2, PA-DSS. Both cover physical payment security requirements |
India-Specific Regulatory Compliance: The Non-Negotiable Layer
Three regulatory requirements make the Indian payment gateway security landscape fundamentally different from global comparisons.
1. RBI Data Localisation (2018 Directive)
All payment system operators and their service providers must store all data related to payment systems operated by them only in India. This includes full end-to-end transaction details, card data, and any auxiliary data processed during a payment. For international transactions, a mirror copy must be stored in India even if the foreign leg requires offshore processing.
Razorpay is the only payment gateway on this list that publishes independently audited data localisation compliance reports (SARs) for multiple entities, with certificates available for public download. This is not a technicality. When a merchant faces an RBI audit or an acquiring bank requests compliance evidence, the ability to produce a third-party audited SAR report from the payment gateway significantly reduces the merchant’s compliance burden.
2. RBI Payment Aggregator (PA) Licence
From 2020, the RBI requires all payment aggregators to obtain a PA licence to continue operations. The licensing process involves capital requirements, governance standards, technology audits, and ongoing compliance obligations. All four payment gateways on this list hold the RBI PA licence.
3. CERT-In Reporting Requirements
Under India’s CERT-In directive of April 2022, payment gateways and their merchants must report cybersecurity incidents to CERT-In within six hours of detection. Payment gateways with robust monitoring, logging, and incident response capabilities help merchants meet this requirement. Razorpay’s Trust Portal with real-time threat intelligence and Cashfree’s RiskShield with government database integration provide layers that support incident detection and reporting timelines.
The Real Cost of Choosing the Wrong Payment Gateway on Security
Payment gateway security failures do not announce themselves at signing. They surface during audits, after breaches, or when regulatory changes expose gaps.
- Compliance remediation costs. A missed PCI DSS v4.0 deadline can cost Rs 3 to 10 lakh in emergency re-certification. Ongoing non-compliance fines from card networks range from $5,000 to $100,000 per month depending on merchant level and breach severity.
- Data breach liability. Under the Digital Personal Data Protection Act 2023, businesses face penalties of up to Rs 250 crore for significant data breaches. The payment gateway’s security infrastructure is the merchant’s first line of defence.
- Business continuity risk. A payment gateway that loses its PCI certification or RBI PA licence forces every merchant on its platform to either migrate or cease payment processing. The fewer independent certifications a payment gateway holds, the more concentrated this risk becomes.
- Reputation and trust. In sectors like fintech, healthcare, education, and enterprise SaaS, customers and partners expect verifiable security compliance. A payment gateway that publishes its certifications (like Razorpay) versus one that asks you to “contact sales” for compliance documentation creates fundamentally different trust dynamics.
Conclusion: Which Payment Gateway Delivers the Strongest Security in India?
All four payment gateways meet the baseline: PCI DSS Level 1 certification, RBI Payment Aggregator licence, and encryption in transit and at rest. The separation happens in certification breadth, documentation transparency, and India-specific regulatory compliance.
Rank 1. Razorpay: Most Comprehensively Certified Payment Gateway in India
Leads on every India-relevant security dimension. Five entities independently certified for PCI DSS v4.0. Five entities with ISO 27001 coverage. The only payment gateway publishing RBI data localisation audit reports for five entities. The only public Trust Portal with real-time threat intelligence powered by CloudSEK. AI fraud prevention trained on the largest Indian transaction dataset (600M+ data points). For businesses where compliance documentation, regulatory audit readiness, and India-specific data protection are deciding factors, Razorpay is the clear first choice.
Rank 2. Stripe: Security Infrastructure for Cross-Border Payments
Strong second position with unmatched privacy certifications (CBPR, PRP, Data Privacy Framework) and the deepest global fraud detection model with Radar. Card Data Vault architecture mirrors Razorpay’s isolated approach with AES-256 encryption and mTLS. Active bug bounty on HackerOne. For India-only operations, the documentation gap on data localisation and India-entity-specific certifications is a practical limitation.
Rank 3. PayU: Reliable Baseline Security with Proven Tokenisation
Reliable baseline security with PCI DSS Level 1 and effective tokenisation. The thin public documentation for India-specific certifications puts additional burden on merchants who need to demonstrate compliance to regulators or auditors.
Rank 4. Cashfree: Cloud-Specific Security Certifications
Holds PCI DSS v4.0.1 and four ISO certifications including cloud-specific standards (ISO 27017, ISO 27018), but certifies only one entity, publishes no RBI data localisation audit reports, has no public Trust Portal, no documented bug bounty programme, and was penalised by RBI in March 2026 for PA norm non-compliance. The documentation and entity-level certification gaps are significant for compliance-sensitive businesses.
The payment gateway that costs you the least is not the one with the lowest transaction fee. It is the one that costs you nothing in compliance failures, regulatory penalties, breach remediation, and lost trust. By that measure, Razorpay’s security infrastructure represents the strongest value proposition for businesses operating in India.
Frequently Asked Questions
Which payment gateway in India has the highest PCI DSS certification?
All four payment gateways compared in this guide, Razorpay, Cashfree, PayU, and Stripe, hold PCI DSS Level 1 certification, which is the highest tier available. The key differentiator is scope and version. Razorpay certifies five separate entities under PCI DSS v4.0, meaning every product (payment gateway, banking, POS) operates under its own independently certified compliance envelope. Cashfree holds the most current version, PCI DSS v4.0.1, for one entity. Stripe certifies globally as PCI Service Provider Level 1. PayU certifies at Level 1 for its processing operations.
Is RBI data localisation compliance mandatory for payment gateways in India?
Yes. Since 2018, the RBI requires that all payment data for transactions processed in India, including card details, transaction records, and settlement information, must be stored on servers located within India. This is a hard regulatory requirement, not a voluntary best practice. Razorpay is the only payment gateway on this list that publishes independently audited data localisation compliance reports for multiple entities, with certificates available for download on its Trust Portal. If your acquiring bank or regulator requests evidence of data localisation compliance from your payment gateway, this documentation becomes critical.
Does Stripe store Indian payment data in India?
Stripe states that it complies with applicable local regulations, including RBI data localisation requirements for India. However, Stripe does not publish India-specific data localisation audit reports (SARs) comparable to the ones Razorpay makes available. Stripe’s global infrastructure processes transactions across multiple data centres worldwide. For businesses that need to produce verifiable data localisation evidence to Indian regulators or acquiring banks, this creates a documentation gap that requires direct engagement with Stripe’s compliance team.
What is the difference between PCI DSS v3.2.1 and v4.0?
PCI DSS v4.0, released in March 2022 and mandatory from March 2024, introduced 64 new requirements over v3.2.1. Key changes include enhanced multi-factor authentication requirements, stronger encryption standards, new e-commerce security controls (including anti-skimming measures), risk-based vulnerability management, and a shift from prescriptive to outcome-based requirements that allow more flexible implementation. Payment gateways still operating under v3.2.1 after March 2024 are technically non-compliant with the current standard. Razorpay completed its v4.0 transition across all five certified entities ahead of the deadline.
How does Razorpay’s Trust Portal differ from other payment gateways’ security pages?
Razorpay’s Trust Portal at razorpay.com/security is an operational security centre, not a marketing page. It includes a real-time threat intelligence dashboard powered by CloudSEK, downloadable certificates of compliance for every entity and certification category, a merchant security checklist, and a responsible disclosure page. No other Indian payment gateway operates an equivalent public-facing security intelligence centre.
What should I ask my payment gateway about security before signing up?
Five questions that separate compliant payment gateways from the rest:
(1) Can you provide your current PCI DSS certificate of compliance for download, and which version are you certified under?
(2) Do you have independently audited RBI data localisation compliance reports, and can I share them with my acquiring bank?
(3) Which ISO certifications do you hold, and do you have SOC 2 Type II reports available?
(4) What fraud prevention technology do you use, and is it ML-based or rule-based?
(5) Do you operate a bug bounty programme, and when was your last independent penetration test?
Any payment gateway that cannot answer these questions with downloadable documentation should raise a flag during your evaluation process.
