WhichPayroll Security Disclosure Benchmark
Security certification and disclosure quality across 17 EOR and global payroll providers.
v1 · Last updated: 2026-06-06 · Sample: 17 providers · Next refresh: Aug 2026
WhichPayroll sample of 17 providers. Observed May 2026. Verified = confirmed from public provider documentation. Methodology →
What this benchmark measures
The WhichPayroll Security Disclosure Benchmark records what security certifications and compliance documentation each provider makes publicly verifiable, without requiring an NDA, a sales call, or a vendor questionnaire response. The benchmark covers six certification dimensions: SOC 2 Type II, ISO 27001, GDPR data processing agreements, HIPAA, PCI DSS, and Cyber Essentials Plus.
Each dimension is classified as: Verified (certification confirmed from public provider documentation), Public (public-facing compliance document available but formal certification not stated), On request (provider states certification is available on request), or not disclosed (no public evidence found). Not disclosed does not mean the provider lacks the certification; it means WhichPayroll could not confirm it without a vendor questionnaire.
Key findings
In WhichPayroll’s sample of 17 providers observed in May 2026:
- 12 of 17 providers have verified SOC 2 Type II from public sources. Deel, Papaya Global, Rippling, Pebl, Multiplier, G-P, Plane, Playroll, RemotePeople, Lano, Remofirst and Gusto all publish or explicitly reference current SOC 2 Type II attestation on their trust centres or security pages. A further 2, Remote and Oyster HR, state SOC 2 is available on request. Re-checked at source on 5 August 2026, which added Pebl and Remofirst: both state the certification plainly on their own pages, and both had been recorded as undisclosed because the check ran against a pre-rebrand URL in Pebl’s case and missed the trust-signals block in Remofirst’s.
- 10 of 17 have verified ISO 27001 from public documentation. Overlap with SOC 2 is high: providers with both certifications tend to publish them together. Only 1 provider, Safeguard Global, discloses neither certification publicly.
- 9 of 17 publish a GDPR data processing agreement you can actually read: a DPA reachable without a login, an NDA or a sales enquiry. Re-assessed at source on 5 August 2026 under a tighter rule than the earlier count used, which had credited a privacy FAQ or a stated DPA-on-request process; on that looser test the figure was 14. The remaining 8 publish nothing that meets the standard. Safeguard Global is the clearest case: it publishes a page headed GDPR specifications, but that document is expressly controller-to-controller and covers only business contact data, so it is not a processor DPA.
- 0 of 17 providers disclose Cyber Essentials Plus. This UK government-backed certification is standard practice for UK government suppliers. Its absence from all 17 providers in the sample reflects that most EOR platforms are US-headquartered and do not pursue UK-specific government certifications.
- PCI DSS is not disclosed by any provider in this sample, and HIPAA by 3. PCI DSS applies to payment card handling, which is niche in the EOR context. HIPAA is not a certification at all, so no provider can be verified against it, but three now document how they handle protected health information: Gusto states on its own security page that it follows HIPAA guidelines and maintains business associate agreements, Rippling publishes HIPAA-scoped audit reports through its trust centre, and Playroll refers to HIPAA-compliant configurations without evidence behind the claim.
Buyer implications
Buyers in regulated industries (financial services, healthcare, government contractors) typically require SOC 2 Type II reports and ISO 27001 certificates before procurement approval. The 12 providers with verified SOC 2 all represent viable choices on this dimension. For the 5 providers where SOC 2 is not publicly verified, submit a security questionnaire early in the sales cycle and request the SOC 2 Type II report directly. Waiting until contract stage for this document routinely adds 2–4 weeks to procurement timelines.
For GDPR compliance specifically, any provider handling EU employee payroll data is a data processor under GDPR Article 28. Even where a public DPA document is not listed, providers are legally required to execute a DPA on request. The 3 providers with no public GDPR reference are not necessarily non-compliant; they may not be marketing their GDPR documentation publicly.
Limitations
- Not disclosed does not mean the provider lacks certification. Providers frequently hold certifications that are not surfaced in public documentation. This benchmark records public disclosure, not certification status.
- Certification status changes. Providers obtain, renew, or let lapse certifications on their own cycles. WhichPayroll’s observation is a point-in-time record from May 2026.
- This benchmark does not assess underlying security quality, MFA enforcement, penetration testing disclosure, or bug bounty scope. Those dimensions will be added in the Aug 2026 refresh.
Security certification disclosure matrix
| Provider | SOC 2 Type II | ISO 27001 | GDPR DPA | HIPAA | PCI DSS | Cyber Essentials+ | Composite | Confidence |
|---|---|---|---|---|---|---|---|---|
| Deel | Verified | Verified | Public | — | — | — | 9.1 /10 | High |
| Multiplier | Verified | Verified | Public | — | — | — | 8.5 /10 | Medium |
| Pebl | Verified | Verified | Public | — | — | — | 8.1 /10 | Medium |
| RemotePeople | Verified | Verified | Public | — | — | — | 8.0 /10 | Medium |
| Rippling | Verified | Verified | Public | On request | — | — | 6.4 /10 | Medium |
| Remofirst | Verified | Verified | — | — | — | — | 8.1 /10 | Medium |
| Papaya Global | Verified | Verified | — | — | — | — | 7.7 /10 | High |
| G-P | Verified | On request | Public | — | — | — | 9.5 /10 | Medium |
| Remote | On request | Verified | Public | — | — | — | 8.0 /10 | High |
| Lano | Verified | — | Claimed | — | — | — | 7.8 /10 | Medium |
| WorkMotion | — | Verified | Public | — | — | — | 7.7 /10 | Medium |
| Playroll | Verified | Claimed | — | Claimed | — | — | 7.5 /10 | Medium |
| Atlas HXM | — | Verified | — | — | — | — | 7.2 /10 | Medium |
| Plane | Verified | — | — | — | — | — | 6.7 /10 | Medium |
| Gusto | Verified | — | — | Public | — | — | 3.5 /10 | Medium |
| Oyster HR | On request | — | Public | — | — | — | 7.0 /10 | Medium |
| Safeguard Global | — | — | — | — | — | — | 4.2 /10 | Medium |
Research conducted using WhichPayroll’s evidence-first methodology. View full methodology →
WhichPayroll Research, [Report name], [Month Year]. Available at whichpayroll.com/research/[slug]/. Sample: [N] providers. Last updated: [date].
For data requests or corrections: contact@whichpayroll.com